Search Results (323598 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-3753 1 Merge-object Project 1 Merge-object 2024-11-21 N/A
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
CVE-2018-3752 1 Merge-options Project 1 Merge-options 2024-11-21 N/A
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
CVE-2018-3751 1 Umbraengineering 1 Merge-recursive 2024-11-21 N/A
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
CVE-2018-3750 2 Deep Extend Project, Redhat 3 Deep Extend, Enterprise Linux, Rhel Software Collections 2024-11-21 N/A
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
CVE-2018-3749 1 Deap Project 1 Deap 2024-11-21 N/A
The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
CVE-2018-3748 1 Glance Project 1 Glance 2024-11-21 N/A
There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name.
CVE-2018-3747 1 Public.js Project 1 Public.js 2024-11-21 N/A
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
CVE-2018-3746 1 Pdfinfojs Project 1 Pdfinfojs 2024-11-21 9.8 Critical
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
CVE-2018-3745 1 Atob Project 1 Atob 2024-11-21 9.1 Critical
atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
CVE-2018-3744 1 Html-pages Project 1 Html-pages 2024-11-21 9.8 Critical
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
CVE-2018-3743 1 Hekto Project 1 Hekto 2024-11-21 6.1 Medium
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
CVE-2018-3741 2 Redhat, Rubyonrails 2 Cloudforms Managementengine, Html Sanitizer 2024-11-21 6.1 Medium
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.
CVE-2018-3740 1 Sanitize Project 1 Sanitize 2024-11-21 N/A
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
CVE-2018-3739 1 Https-proxy-agent Project 1 Https-proxy-agent 2024-11-21 N/A
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
CVE-2018-3738 1 Protobufjs Project 1 Protobufjs 2024-11-21 5.5 Medium
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
CVE-2018-3737 2 Joyent, Redhat 2 Sshpk, Rhel Software Collections 2024-11-21 7.5 High
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
CVE-2018-3735 1 Bracket-template Project 1 Bracket-template 2024-11-21 6.1 Medium
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
CVE-2018-3734 1 Stattic Project 1 Stattic 2024-11-21 7.5 High
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.
CVE-2018-3733 1 Crud-file-server Project 1 Crud-file-server 2024-11-21 7.5 High
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
CVE-2018-3732 1 Resolve-path Project 1 Resolve-path 2024-11-21 7.5 High
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path.