VYPR

rpm package

suse/nodejs14&distro=SUSE Linux Enterprise Module for Web and Scripting 12

pkg:rpm/suse/nodejs14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012

Vulnerabilities (49)

  • CVE-2021-22918Jul 12, 2021
    affected < 14.17.2-6.12.1fixed 14.17.2-6.12.1

    Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. Th

  • CVE-2021-23343May 4, 2021
    affected < 14.19.0-6.24.1fixed 14.19.0-6.24.1

    All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

  • CVE-2021-23362Mar 23, 2021
    affected < 14.17.2-6.12.1fixed 14.17.2-6.12.1

    The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.

  • CVE-2021-27290Mar 12, 2021
    affected < 14.17.2-6.12.1fixed 14.17.2-6.12.1

    ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

  • CVE-2021-22883Mar 3, 2021
    affected < 14.16.0-6.9.2fixed 14.16.0-6.9.2

    Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then th

  • CVE-2021-22884Mar 3, 2021
    affected < 14.16.0-6.9.2fixed 14.16.0-6.9.2

    Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker control

  • CVE-2020-8265Jan 6, 2021
    affected < 14.15.4-6.6.1fixed 14.15.4-6.6.1

    Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If t

  • CVE-2020-8287Jan 6, 2021
    affected < 14.15.4-6.6.1fixed 14.15.4-6.6.1

    Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggl

  • CVE-2020-7774Nov 17, 2020
    affected < 14.17.2-6.12.1fixed 14.17.2-6.12.1

    The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

Page 3 of 3