VYPR

Ecstatic

by Ecstatic Project

npm: ecstatic

Source repositories

CVEs (3)

  • CVE-2019-10775HigJan 2, 2020
    risk 0.49cvss 7.5epss 0.01

    ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.

  • CVE-2015-9242HigMay 29, 2018
    risk 0.42cvss 7.5epss 0.02

    Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.

  • CVE-2016-10703HigDec 14, 2017
    risk 0.42cvss 7.5epss 0.03

    A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string.