2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16099 | — | — | 1.6% | Jun 7, 2018 | The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed ... |
| CVE-2017-16098 | — | — | 1.7% | Jun 7, 2018 | charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is requir... |
| CVE-2017-16097 | — | — | 2.0% | Jun 7, 2018 | tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16096 | — | — | 2.0% | Jun 7, 2018 | serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker ... |
| CVE-2017-16095 | — | — | 2.0% | Jun 7, 2018 | serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacke... |
| CVE-2017-16094 | — | — | 2.0% | Jun 7, 2018 | iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker acces... |
| CVE-2017-16093 | — | — | 2.0% | Jun 7, 2018 | cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker acce... |
| CVE-2017-16092 | — | — | 2.0% | Jun 7, 2018 | Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an... |
| CVE-2017-16091 | — | — | 1.8% | Jun 7, 2018 | xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, givi... |
| CVE-2017-16090 | — | — | 2.0% | Jun 7, 2018 | fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access t... |
| CVE-2017-16089 | — | — | 2.0% | Jun 7, 2018 | serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16088 | — | — | 3.5% | Jun 7, 2018 | The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized use... |
| CVE-2017-16086 | — | — | 9.2% | Jun 7, 2018 | ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o... |
| CVE-2017-16085 | — | — | 2.0% | Jun 7, 2018 | tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacke... |
| CVE-2017-16084 | — | — | 2.0% | Jun 7, 2018 | list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable... |
| CVE-2017-16083 | — | — | 2.0% | Jun 7, 2018 | node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, g... |
| CVE-2017-16082 | — | — | 10.5% | Jun 7, 2018 | A remote code execution vulnerability was found within the pg module when the remote database or query specifies a speci... |
| CVE-2017-16081 | — | — | 1.3% | Jun 7, 2018 | cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b... |
| CVE-2017-16080 | — | — | 1.1% | Jun 7, 2018 | nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np... |
| CVE-2017-16079 | — | — | 1.1% | Jun 7, 2018 | smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
| CVE-2017-16078 | — | — | 1.1% | Jun 7, 2018 | shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by ... |
| CVE-2017-16077 | — | — | 1.2% | Jun 7, 2018 | mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm... |
| CVE-2017-16076 | — | — | 1.1% | Jun 7, 2018 | proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np... |
| CVE-2017-16075 | — | — | 1.2% | Jun 7, 2018 | http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished ... |
| CVE-2017-16074 | — | — | 1.2% | Jun 7, 2018 | crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now