Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,514 CVEs tagged with CWE-31058 Critical, 302 High, 2,014 Medium, 140 Low, 0 Unrated.

CVE-2016-10614

Published Jun 1, 2018

httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execut…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10613

Published Jun 1, 2018

bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10612

Published Jun 1, 2018

dalek-browser-ie-canary is Internet Explorer bindings for DalekJS. dalek-browser-ie-canary downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10610

Published Jun 1, 2018

unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10608

Published Jun 1, 2018

robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10605

Published Jun 1, 2018

dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10604

Published Jun 1, 2018

dalek-browser-chrome is Google Chrome bindings for DalekJS. dalek-browser-chrome downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possib…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10603

Published Jun 1, 2018

air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code e…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10602

Published Jun 1, 2018

haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10600

Published Jun 1, 2018

webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10598

Published Jun 1, 2018

arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10596

Published Jun 1, 2018

imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be poss…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10595

Published Jun 1, 2018

jdf-sass is a fork from node-sass, jdf use only. jdf-sass downloads executable resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10594

Published Jun 1, 2018

ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP, which leaves it vulnerable t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10588

Published Jun 1, 2018

nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10587

Published Jun 1, 2018

wasdk is a toolkit for creating WebAssembly modules. wasdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote cod…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10585

Published Jun 1, 2018

libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl downloads zipped resources over HTTP, which leaves it vulnerabl…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10583

Published Jun 1, 2018

closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10581

Published Jun 1, 2018

Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer productivity. steroids downloads zipped resources over HTTP…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 176-200 of 2,514 CVEsPage 8 of 101