Joyent Node.Js vulnerabilities
2 known vulnerabilities affecting joyent/node.js.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2014-7192CRITICALCVSS 10.0PoC≤ 0.10.322014-12-11
CVE-2014-7192 [CRITICAL] CWE-94 CVE-2014-7192: Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
nvd
CVE-2014-6394HIGHCVSS 7.5≤ 0.8.3v0.8.0+2 more2014-10-08
CVE-2014-6394 [HIGH] CWE-22 CVE-2014-6394: visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a director
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
nvd