Known vulnerabilities in Node.js 10.3.0

Software: Node.js
Version: 10.3.0
Software CPE: cpe:2.3:a:node_js_foundation:nodejs:*:*:*:*:*:*:*:*
Total vulnerabilities: 26
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Node.js version 10.3.0 Node.js 10.3.0 is affected by 26 vulnerabilities: 3 high, 11 medium, 12 low Critical High Medium Low

Vulnerabilities (26)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU50955 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-22884
CWE-350 Medium
No
No
10.24.0, 12.21.0, 14.16.0, 15.10.0 25.02.2021 SB2021022530
SB2021022532
SB2021022616
and 38 more
#VU50954 - Resource Management Errors
CVE-2021-22883
CWE-399 Medium
No
No
10.24.0, 12.21.0, 14.16.0, 15.10.0 25.02.2021 SB2021022530
SB2021022532
SB2021022614
and 36 more
#VU50745 - Improper input validation
CVE-2021-23840
CWE-20 Medium
No
No
10.24.0, 12.21.0, 14.16.0, 15.10.0 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 83 more
#VU49254 - Use After Free
CVE-2020-8265
CWE-416 Medium
No
No
10.23.1, 12.20.1, 14.15.4, 15.5.1 04.01.2021 SB2021010419
SB2021010704
SB2021010705
and 33 more
#VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8287
CWE-444 Medium
Public exploit available
No
10.23.1, 12.20.1, 14.15.4, 15.5.1 04.01.2021 SB2021010419
SB2021010706
SB2021010707
and 33 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Public exploit available
No
10.23.1, 12.20.1, 14.15.4 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more
#VU47248 - Buffer overflow
CVE-2020-8252
CWE-120 High
No
No
10.22.1, 12.18.4, 14.9.0 18.09.2020 SB2020100117
SB2020091824
SB2020091825
and 19 more
#VU28539 - Memory corruption
CVE-2020-8174
CWE-119 High
No
No
10.21.0, 12.18.0, 14.4.0 03.06.2020 SB2020060305
SB2020060607
SB2020072216
and 20 more
#VU28538 - Resource exhaustion
CVE-2020-11080
CWE-400 Medium
No
No
10.21.0, 12.18.0, 14.4.0 03.06.2020 SB2020060305
SB2020060607
SB2020060703
and 42 more
#VU26284 - Resource exhaustion
CVE-2019-5737
CWE-400 Medium
No
No
6.17.0, 8.15.1, 10.15.2, 11.10.1 20.03.2020 SB2019032825
SB2020032103
SB2019041610
and 6 more
#VU26149 - Integer overflow
CVE-2020-10531
CWE-190 High
No
No
10.21.0 17.03.2020 SB2020031801
SB2020031802
SB2020031803
and 40 more
#VU25014 - Reachable Assertion
CVE-2019-15604
CWE-617 Medium
No
No
10.19.0, 12.15.0, 13.8.0 06.02.2020 SB2020020615
SB2020022426
SB2020022514
and 10 more
#VU25013 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-15605
CWE-444 Medium
No
No
10.19.0, 12.15.0, 13.8.0 06.02.2020 SB2020020615
SB2020022426
SB2020022514
and 19 more
#VU25012 - Improper input validation
CVE-2019-15606
CWE-20 Medium
No
No
10.19.0, 12.15.0, 13.8.0 06.02.2020 SB2020020615
SB2020022426
SB2020022514
and 11 more
#VU16170 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2018-12123
CWE-451 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 5 more
#VU16169 - Resource exhaustion
CVE-2018-12122
CWE-400 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 5 more
#VU16168 - Heap-based Buffer Overflow
CVE-2018-12121
CWE-122 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 8 more
#VU15723 - Information Exposure Through Timing Discrepancy
CVE-2018-5407
CWE-208 Low
Public exploit available
No
6.15.0, 8.14.0, 10.9 06.11.2018 SB2018110602
SB2018111301
SB2018112201
and 30 more
#VU15668 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0734
CWE-200 Low
No
No
10.14.0, 11.3.0 01.11.2018 SB2018110102
SB2018112201
SB2018112602
and 39 more
#VU15568 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0735
CWE-200 Low
No
No
6.15.0, 8.14.0, 10.14.0, 11.3.0 29.10.2018 SB2018110102
SB2018112602
SB2018112906
and 8 more


Showing elements 1 - 20 out of 26