Vulnerabilities (CVE)

Filtered by CWE-200
Total 8367 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16061 1 Tkinter Package 1 Tkinter 2024-11-21 5.0 MEDIUM 7.5 HIGH
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16060 1 Babelcli Project 1 Babelcli 2024-11-21 5.0 MEDIUM 7.5 HIGH
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16059 1 Mssql-node Project 1 Mssql-node 2024-11-21 5.0 MEDIUM 7.5 HIGH
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16058 1 Gruntcli Project 1 Gruntcli 2024-11-21 5.0 MEDIUM 7.5 HIGH
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16057 1 Nodemssql Project 1 Nodemssql 2024-11-21 5.0 MEDIUM 7.5 HIGH
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16056 1 Mssql.js Project 1 Mssql.js 2024-11-21 5.0 MEDIUM 7.5 HIGH
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16055 1 Sqlserver Project 1 Sqlserver 2024-11-21 5.0 MEDIUM 7.5 HIGH
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16054 1 Nodefabric Project 1 Nodefabric 2024-11-21 5.0 MEDIUM 7.5 HIGH
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16053 1 Fabric-js Project 1 Fabric-js 2024-11-21 5.0 MEDIUM 7.5 HIGH
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16052 1 Node-fabric Project 1 Node-fabric 2024-11-21 5.0 MEDIUM 7.5 HIGH
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16051 1 Sqliter Project 1 Sqliter 2024-11-21 5.0 MEDIUM 7.5 HIGH
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16050 1 Sqlite.js Project 1 Sqlite.js 2024-11-21 5.0 MEDIUM 7.5 HIGH
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16049 1 Nodesqlite Project 1 Nodesqlite 2024-11-21 5.0 MEDIUM 7.5 HIGH
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16048 1 Node-sqlite Project 1 Node-sqlite 2024-11-21 5.0 MEDIUM 7.5 HIGH
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16047 1 Mysqljs Project 1 Mysqljs 2024-11-21 5.0 MEDIUM 7.5 HIGH
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16045 1 Jquery.js Project 1 Jquery.js 2024-11-21 5.0 MEDIUM 7.5 HIGH
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16044 1 D3.js Project 1 D3.js 2024-11-21 5.0 MEDIUM 7.5 HIGH
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16024 2 Nodejs, Sync-exec Project 2 Node.js, Sync-exec 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.
CVE-2017-15852 1 Google 1 Android 2024-11-21 4.6 MEDIUM 7.8 HIGH
Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.
CVE-2017-15851 1 Google 1 Android 2024-11-21 4.6 MEDIUM 7.8 HIGH
Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel