Known vulnerabilities in nodejs-current (Alpine package)

Software CPE: cpe:2.3:o:alpine:nodejs-current_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 29
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nodejs-current (Alpine package) nodejs-current (Alpine package) is affected by 29 known vulnerabilities: 4 high, 15 medium, 10 low Critical High Medium Low

Vulnerabilities (29)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU50955 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-22884
CWE-350 Medium
No
No
15.10.0-r0 25.02.2021 SB2021022530
SB2021022532
SB2021022616
and 38 more
#VU50954 - Resource Management Errors
CVE-2021-22883
CWE-399 Medium
No
No
15.10.0-r0 25.02.2021 SB2021022530
SB2021022532
SB2021022614
and 36 more
#VU49254 - Use After Free
CVE-2020-8265
CWE-416 Medium
No
No
15.5.1-r0 04.01.2021 SB2021010419
SB2021010704
SB2021010705
and 33 more
#VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8287
CWE-444 Medium
Available
No
15.5.1-r0 04.01.2021 SB2021010419
SB2021010706
SB2021010707
and 33 more
#VU48569 - Resource Management Errors
CVE-2020-8277
CWE-399 Medium
Available
No
15.3.0-r0 19.11.2020 SB2020112003
SB2020112005
SB2020102133
and 23 more
#VU47217 - Resource exhaustion
CVE-2020-8251
CWE-400 Medium
No
No
14.11.0-r0 18.09.2020 SB2020091030
SB2021011107
SB2020121121
and 3 more
#VU47218 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8201
CWE-444 High
No
No
14.11.0-r0 18.09.2020 SB2020091028
SB2020091029
SB2020100608
and 12 more
#VU28539 - Memory corruption
CVE-2020-8174
CWE-119 High
No
No
14.4.0-r0 03.06.2020 SB2020060305
SB2020060607
SB2020072216
and 20 more
#VU28538 - Resource exhaustion
CVE-2020-11080
CWE-400 Medium
No
No
14.4.0-r0 03.06.2020 SB2020060305
SB2020060607
SB2020060703
and 42 more
#VU28537 - Improper Authorization
CVE-2020-8172
CWE-285 Medium
No
No
14.4.0-r0 03.06.2020 SB2020060305
SB2020060364
SB2020060365
and 9 more
#VU26284 - Resource exhaustion
CVE-2019-5737
CWE-400 Medium
No
No
11.10.1-r0 20.03.2020 SB2019032825
SB2020032103
SB2019041610
and 6 more
#VU25014 - Reachable Assertion
CVE-2019-15604
CWE-617 Medium
No
No
13.11.0-r0 06.02.2020 SB2020020615
SB2020022426
SB2020022514
and 10 more
#VU25013 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-15605
CWE-444 Medium
No
No
13.11.0-r0 06.02.2020 SB2020020615
SB2020022426
SB2020022514
and 19 more
#VU25012 - Improper input validation
CVE-2019-15606
CWE-20 Medium
No
No
13.11.0-r0 06.02.2020 SB2020020615
SB2020022426
SB2020022514
and 11 more
#VU16170 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2018-12123
CWE-451 Low
No
No
11.3.0-r0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 5 more
#VU16169 - Resource exhaustion
CVE-2018-12122
CWE-400 Low
No
No
11.3.0-r0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 5 more
#VU16168 - Heap-based Buffer Overflow
CVE-2018-12121
CWE-122 Low
No
No
11.3.0-r0 29.11.2018 SB2018112906
SB2019012702
SB2019012803
and 8 more
#VU15668 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0734
CWE-200 Low
No
No
11.3.0-r0 01.11.2018 SB2018110102
SB2018112201
SB2018112602
and 39 more
#VU15568 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0735
CWE-200 Low
No
No
11.3.0-r0 29.10.2018 SB2018110102
SB2018112602
SB2018112906
and 8 more
#VU11294 - Resource exhaustion
CVE-2018-0739
CWE-400 Low
No
No
7.2.1-r2, 7.10.1-r1 28.03.2018 SB2018032804
SB2018032903
SB2018033002
and 35 more


Showing elements 1 - 20 out of 29