2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-16099The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed ...
CVE-2017-16098charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is requir...
CVE-2017-16097tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16096serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker ...
CVE-2017-16095serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacke...
CVE-2017-16094iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker acces...
CVE-2017-16093cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker acce...
CVE-2017-16092Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an...
CVE-2017-16091xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, givi...
CVE-2017-16090fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access t...
CVE-2017-16089serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16088The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized use...
CVE-2017-16086ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o...
CVE-2017-16085tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacke...
CVE-2017-16084list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable...
CVE-2017-16083node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, g...
CVE-2017-16082A remote code execution vulnerability was found within the pg module when the remote database or query specifies a speci...
CVE-2017-16081cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b...
CVE-2017-16080nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np...
CVE-2017-16079smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by ...
CVE-2017-16077mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...
CVE-2017-16076proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np...
CVE-2017-16075http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished ...
CVE-2017-16074crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now