Filtered by CWE-506
Total 49 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-2003 2 Unitronics, Unitronicsplc 3 Vision1210, Vision1210, Vision1210 Firmware 2024-10-30 9.1 Critical
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.
CVE-2017-16070 1 Nodecaffe Project 1 Nodecaffe 2024-09-17 N/A
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16066 1 Opencv.js Project 1 Opencv.js 2024-09-17 N/A
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16077 1 Mongose Project 1 Mongose 2024-09-17 N/A
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16060 1 Babelcli Project 1 Babelcli 2024-09-17 N/A
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16064 1 Node-openssl Project 1 Node-openssl 2024-09-17 N/A
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16202 1 Cofeescript Project 1 Cofeescript 2024-09-17 N/A
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16049 1 Nodesqlite Project 1 Nodesqlite 2024-09-17 N/A
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16074 1 Crossenv Project 1 Crossenv 2024-09-17 N/A
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16051 1 Sqliter Project 1 Sqliter 2024-09-17 N/A
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16071 1 Nodemailer-js Project 1 Nodemailer-js 2024-09-17 N/A
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16207 1 Discordi.js Project 1 Discordi.js 2024-09-17 N/A
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
CVE-2017-16068 1 Ffmepg Project 1 Ffmepg 2024-09-17 N/A
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16055 1 Sqlserver Project 1 Sqlserver 2024-09-17 N/A
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16052 1 Node-fabric Project 1 Node-fabric 2024-09-17 N/A
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16065 1 Openssl.js Project 1 Openssl.js 2024-09-17 N/A
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16044 1 D3.js Project 1 D3.js 2024-09-17 N/A
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16057 1 Nodemssql Project 1 Nodemssql 2024-09-17 N/A
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16076 1 Proxy.js Project 1 Proxy.js 2024-09-17 N/A
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16059 1 Mssql-node Project 1 Mssql-node 2024-09-17 N/A
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.