Ua-Parser-Js Project Ua-Parser-Js vulnerabilities
5 known vulnerabilities affecting ua-parser-js_project/ua-parser-js.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5
Vulnerabilities
Page 1 of 1
CVE-2022-25927HIGHCVSS 7.5≥ 0.7.30, < 0.7.33≥ 0.8.1, < 1.0.332023-01-26
CVE-2022-25927 [HIGH] CWE-1333 CVE-2022-25927: Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are
Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
cvelistv5ghsanvdosv
CVE-2021-4229HIGHCVSS 8.8v0.7.29v0.8.0+1 more2022-05-24
CVE-2021-4229 [HIGH] CWE-912 CVE-2021-4229: A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This is
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.
ghsanvdosv
CVE-2021-27292HIGHCVSS 7.5≥ 0.7.14, < 0.7.242021-03-17
CVE-2021-27292 [HIGH] CVE-2021-27292: ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of
ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.
ghsanvdosv
CVE-2020-7793HIGHCVSS 7.5fixed in 0.7.23≥ unspecified, < 0.7.232020-12-11
CVE-2020-7793 [HIGH] CVE-2020-7793: The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
cvelistv5ghsanvdosv
CVE-2020-7733HIGHCVSS 7.5fixed in 0.7.22≥ unspecified, < 0.7.222020-09-16
CVE-2020-7733 [HIGH] CWE-400 CVE-2020-7733: The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
cvelistv5ghsanvdosv