Lucene search

K

Cli Node Module Security Vulnerabilities

cve
cve

CVE-2017-16155

fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the...

7.5CVSS

7.5AI Score

0.004EPSS

2018-06-07 02:29 AM
35
cve
cve

CVE-2016-10657

co-cli-installer downloads the co-cli module as part of the install process, but does so over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the....

8.1CVSS

8.3AI Score

0.002EPSS

2018-06-04 04:29 PM
23
cve
cve

CVE-2016-10597

cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM...

5.9CVSS

5.6AI Score

0.001EPSS

2018-06-01 06:29 PM
21
cve
cve

CVE-2016-10560

galenframework-cli is the node wrapper for the Galen Framework. galenframework-cli below 2.3.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled...

8.1CVSS

8.2AI Score

0.002EPSS

2018-05-31 08:29 PM
27
cve
cve

CVE-2016-10538

The package node-cli before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access...

3.5CVSS

3.9AI Score

0.001EPSS

2018-05-31 08:29 PM
30