CVE-2017-16177
Last Modified: 21 Nov 2024chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16185
Last Modified: 21 Nov 2024uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16193
Last Modified: 21 Nov 2024mfrs is a static file server. mfrs is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16201
Last Modified: 21 Nov 2024zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16204
Last Modified: 21 Nov 2024The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16207
Last Modified: 21 Nov 2024discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
CVE-2017-16212
Last Modified: 21 Nov 2024ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16222
Last Modified: 21 Nov 2024elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request to /../../../etc/passwd, for example, will return a 404 on etc/passwd/index.js.
CVE-2017-16226
Last Modified: 21 Nov 2024The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
CVE-2017-16056
Last Modified: 21 Nov 2024mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16063
Last Modified: 21 Nov 2024node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16070
Last Modified: 21 Nov 2024nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078
Last Modified: 21 Nov 2024shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16082
Last Modified: 21 Nov 2024A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
CVE-2017-16085
Last Modified: 21 Nov 2024tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16093
Last Modified: 21 Nov 2024cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16095
Last Modified: 21 Nov 2024serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16098
Last Modified: 21 Nov 2024charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.
CVE-2017-16101
Last Modified: 21 Nov 2024serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
CVE-2017-16108
Last Modified: 21 Nov 2024gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16206
Last Modified: 21 Nov 2024The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16109
Last Modified: 21 Nov 2024easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.
CVE-2017-16117
Last Modified: 21 Nov 2024slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.
CVE-2017-16125
Last Modified: 21 Nov 2024rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonnection-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16170
Last Modified: 21 Nov 2024liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16178
Last Modified: 21 Nov 2024intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16186
Last Modified: 21 Nov 2024360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16194
Last Modified: 21 Nov 2024picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
CVE-2017-16202
Last Modified: 21 Nov 2024The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16205
Last Modified: 21 Nov 2024The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2018-3711
Last Modified: 21 Nov 2024Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
CVE-2018-3725
Last Modified: 21 Nov 2024hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2017-16057
Last Modified: 21 Nov 2024nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16058
Last Modified: 21 Nov 2024gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16059
Last Modified: 21 Nov 2024mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16060
Last Modified: 21 Nov 2024babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16064
Last Modified: 21 Nov 2024node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16065
Last Modified: 21 Nov 2024openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16066
Last Modified: 21 Nov 2024opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16067
Last Modified: 21 Nov 2024node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16068
Last Modified: 21 Nov 2024ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16069
Last Modified: 21 Nov 2024nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16071
Last Modified: 21 Nov 2024nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16072
Last Modified: 21 Nov 2024nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16073
Last Modified: 21 Nov 2024noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16074
Last Modified: 21 Nov 2024crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16076
Last Modified: 21 Nov 2024proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16079
Last Modified: 21 Nov 2024smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16080
Last Modified: 21 Nov 2024nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16081
Last Modified: 21 Nov 2024cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
