VYPR
Vendor

Browserify

Products
4
CVEs
6
Across products
6
Status
Private

Products

4

Recent CVEs

6
  • CVE-2025-9288CriAug 20, 2025
    risk 0.52cvss 9.1epss 0.01

    Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

  • CVE-2025-9287CriAug 20, 2025
    risk 0.52cvss 9.1epss 0.01

    Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.

  • CVE-2025-6547CriJun 23, 2025
    risk 0.52cvss —epss 0.00

    Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.

  • CVE-2025-6545CriJun 23, 2025
    risk 0.52cvss —epss 0.00

    Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.

  • CVE-2023-46234MedOct 26, 2023
    risk 0.35cvss 6.5epss 0.01

    browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be…

  • CVE-2026-102414LowSep 29, 2026
    risk 0.17cvss 3.7epss 0.00

    pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and…