Skip to main content

Vendor/product archive

serialize-to-js_project / serialize-to-js CVEs

Beta · best-effort

3 CVEs tagged to serialize-to-js_project / serialize-to-js1 Critical, 1 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2019-16772

Published Dec 7, 2019

The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular exp…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-15871

Published Oct 24, 2017

The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function(…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5954

Published Feb 10, 2017

An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code executio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1