Ecstatic
npm: ecstatic
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10775 | Hig | 0.49 | 7.5 | 0.01 | Jan 2, 2020 | ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application. | ||
| CVE-2015-9242 | Hig | 0.42 | 7.5 | 0.02 | May 29, 2018 | Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header. | ||
| CVE-2016-10703 | Hig | 0.42 | 7.5 | 0.03 | Dec 14, 2017 | A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string. |
- risk 0.49cvss 7.5epss 0.01
ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.
- risk 0.42cvss 7.5epss 0.02
Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.
- risk 0.42cvss 7.5epss 0.03
A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string.