VYPR

by Uglifyjs Project

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-8857Cri0.579.80.00Jan 23, 2017The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.
CVE-2015-8858Hig0.497.50.01Jan 23, 2017The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."