VYPR
Vendor
Products
40
CVEs
44
Across products
44
Status
Private

Products

40

Recent CVEs

44
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-0903Cri0.579.80.06Oct 11, 2017RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.
CVE-2017-0899Cri0.579.80.07Aug 31, 2017RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
CVE-2017-0902Hig0.468.10.05Aug 31, 2017RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
CVE-2017-0901Hig0.467.50.19Aug 31, 2017RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
CVE-2018-37260.000.00Jun 7, 2018crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CVE-2017-160640.000.00Jun 7, 2018node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-160810.000.00Jun 7, 2018cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-161450.000.01Jun 7, 2018sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-161770.000.01Jun 7, 2018chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-160880.000.02Jun 7, 2018The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
CVE-2017-162190.000.01Jun 7, 2018yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-160710.000.00Jun 7, 2018nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-160630.000.00Jun 7, 2018node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-161080.000.01Jun 7, 2018gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-161500.000.01Jun 7, 2018wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-161130.000.00Jun 7, 2018The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.
CVE-2017-161300.000.01Jun 7, 2018exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to those with a file extension. Files with no extension such as /etc/passwd throw an error.
CVE-2017-161550.000.01Jun 7, 2018fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-161320.000.01Jun 7, 2018simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-162170.000.01Jun 7, 2018fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.