Latest CVE Feed
-
8.1
HIGHCVE-2016-10564
apk-parser is a tool to extract Android Manifest info from an APK file. apk-parser versions below 0.1.6 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping ou... Read more
Affected Products : apk-parser- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2016-10563
During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This allows for a MITM attack to compromise the integrity of the resources used by this module and could allow for further compromise.... Read more
Affected Products : go-ipfs-dep- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10562
iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested ... Read more
Affected Products : iedriver- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-10561
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.... Read more
Affected Products : bitty- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10560
galenframework-cli is the node wrapper for the Galen Framework. galenframework-cli below 2.3.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the req... Read more
Affected Products : galenframework-cli- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10559
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote cod... Read more
Affected Products : selenium-download- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10558
aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the reques... Read more
Affected Products : aerospike- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2016-10557
appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the request... Read more
Affected Products : appium-chromedriver- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-10556
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated... Read more
Affected Products : sequelize- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-10555
Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server will think the ... Read more
Affected Products : jwt-simple- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10554
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping... Read more
Affected Products : sequelize- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10553
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.... Read more
Affected Products : sequelize- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2016-10552
igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.... Read more
Affected Products : igniteui- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10551
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious... Read more
Affected Products : waterline-sequel- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10550
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in t... Read more
Affected Products : sequelize- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2016-10549
Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Control-Allow-Origin header. This woul... Read more
Affected Products : sails- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10548
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to the `calc` funct... Read more
Affected Products : reduce-css-calc- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10547
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should automatically be escaped. By using an array for the key... Read more
Affected Products : nunjucks- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-10546
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed and may be used to run arbitrar... Read more
Affected Products : pouchdb- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2016-10544
uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibility used compression will shrink said 256mb down to less than 16mb of websocket payload which passes the l... Read more
Affected Products : uws- Published: May. 31, 2018
- Modified: Nov. 21, 2024