Search Results (323221 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-16105 1 Serverwzl Project 1 Serverwzl 2024-11-21 N/A
serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16104 1 Citypredict.whauwiller Project 1 Citypredict.whauwiller 2024-11-21 N/A
citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16103 1 Serveryztyzt Project 1 Serveryztyzt 2024-11-21 N/A
serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16102 1 Serverhuwenhui Project 1 Serverhuwenhui 2024-11-21 N/A
serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16101 1 Serverwg Project 1 Serverwg 2024-11-21 N/A
serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16100 1 Dns-sync Project 1 Dns-sync 2024-11-21 N/A
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
CVE-2017-16099 1 No-case Project 1 No-case 2024-11-21 7.5 High
The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.
CVE-2017-16098 1 Charset Project 1 Charset 2024-11-21 N/A
charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.
CVE-2017-16097 1 Tiny-http Project 1 Tiny-http 2024-11-21 N/A
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16096 1 Serveryaozeyan Project 1 Serveryaozeyan 2024-11-21 N/A
serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16095 1 Serverliujiayi1 Project 1 Serverliujiayi1 2024-11-21 N/A
serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16094 1 Iter-http Project 1 Iter-http 2024-11-21 N/A
iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16093 1 Cyber-js Project 1 Cyber-js 2024-11-21 N/A
cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16092 1 Sencisho Project 1 Sencisho 2024-11-21 N/A
Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16091 1 Xtalk Project 1 Xtalk 2024-11-21 N/A
xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16090 1 Fsk-server Project 1 Fsk-server 2024-11-21 N/A
fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16089 1 Serverlyr Project 1 Serverlyr 2024-11-21 N/A
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16088 1 Safe-eval Project 1 Safe-eval 2024-11-21 N/A
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
CVE-2017-16086 1 Ua-parser Project 1 Ua-parser 2024-11-21 N/A
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
CVE-2017-16085 1 Tinyserver2 Project 1 Tinyserver2 2024-11-21 N/A
tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.