Known vulnerabilities in npm - page 3
Vendor:
OpenAnolis
Software:
npm
Software CPE:
cpe:2.3:o:openanolis:npm:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
96
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
10.8.2-1.20.20.2.1
10.8.2-1.20.20.0.1
10.8.2-1.20.19.2.1
10.8.2-1.20.19.1.1
10.8.1-1.20.16.0.1
8.19.3-1.16.19.1.2.0.2
9.5.0-1.18.14.2.3
6.14.17-1.14.21.1.2.0.1
6.14.15-1.14.18.2.2
6.14.14-1.14.17.5.1
6.14.14-1.12.22.5.1
10.8.2-1.18.20.6.1
10.8.2-1.20.18.2.1
10.7.0-1.18.20.4.1
10.5.0-1.18.20.2.1.0.1
8.19.4-1.16.20.2.4.0.1
10.2.4-1.18.19.1.1.0.1
8.19.4-1.16.20.2.3.0.2
9.8.1-1.18.18.2.1.0.1
9.6.7-1.18.17.1.1.0.2
8.19.4-1.16.20.2.2.0.2
9.5.1-1.18.16.1.1
8.19.4-1.16.20.1.1.0.1
8.19.3-1.16.19.1.1.0.2
6.14.18-1.14.21.3.1.0.1
8.19.1-1.18.9.1.1
8.15.0-1.16.17.1.1
8.11.0-1.16.16.0.3
6.14.17-1.14.20.0.2
6.14.16-1.12.22.12.1
8.1.2-1.16.13.1.3
6.14.13-1.12.22.3.2
6.14.13-1.14.17.3.2
Vulnerabilities (96)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82066 - Exposure of sensitive information to an unauthorized actor CVE-2023-45143 |
CWE-200 | Medium | 9.8.1-1.18.18.2.1.0.1 | 17.10.2023 |
SB2023101702 SB2023101703 SB2023101801 and 31 more |
||
| #VU79335 - Permissions, Privileges, and Access Controls CVE-2023-32559 |
CWE-264 | Medium | 8.19.4-1.16.20.2.2.0.2, 9.6.7-1.18.17.1.1.0.2 | 10.08.2023 |
SB2023081012 SB2023081443 SB2023081705 and 39 more |
||
| #VU79334 - Permissions, Privileges, and Access Controls CVE-2023-32006 |
CWE-264 | Medium | 8.19.4-1.16.20.2.2.0.2, 9.6.7-1.18.17.1.1.0.2 | 10.08.2023 |
SB2023081012 SB2023081443 SB2023081705 and 38 more |
||
| #VU79332 - Permissions, Privileges, and Access Controls CVE-2023-32002 |
CWE-264 | Medium | 8.19.4-1.16.20.2.2.0.2, 9.6.7-1.18.17.1.1.0.2 | 10.08.2023 |
SB2023081012 SB2023081443 SB2023081705 and 44 more |
||
| #VU78932 - Incorrect Regular Expression CVE-2022-25883 |
CWE-185 | Medium | 8.19.4-1.16.20.2.2.0.2, 9.6.7-1.18.17.1.1.0.2 | 03.08.2023 |
SB2023080361 SB2023080362 SB2023081514 and 73 more |
||
| #VU77606 - Inconsistency Between Implementation and Documented Design CVE-2023-30590 |
CWE-1068 | Medium | 8.19.4-1.16.20.1.1.0.1, 9.5.1-1.18.16.1.1 | 21.06.2023 |
SB2023062144 SB2023062727 SB2023062743 and 33 more |
||
| #VU77605 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-30589 |
CWE-444 | Medium | 8.19.4-1.16.20.1.1.0.1, 9.5.1-1.18.16.1.1 | 21.06.2023 |
SB2023062144 SB2023062727 SB2023062743 and 43 more |
||
| #VU77604 - Improper input validation CVE-2023-30588 |
CWE-20 | Medium | 8.19.4-1.16.20.1.1.0.1, 9.5.1-1.18.16.1.1 | 21.06.2023 |
SB2023062144 SB2023062727 SB2023062743 and 33 more |
||
| #VU77586 - Permissions, Privileges, and Access Controls CVE-2023-30581 |
CWE-264 | Medium | 8.19.4-1.16.20.1.1.0.1, 9.5.1-1.18.16.1.1 | 21.06.2023 |
SB2023062144 SB2023062727 SB2023062743 and 31 more |
||
| #VU76426 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CVE-2023-31147 |
CWE-338 | Medium | 8.19.3-1.16.19.1.2.0.2, 9.5.0-1.18.14.2.3 | 23.05.2023 |
SB2023052309 SB2023052312 SB2023053021 and 39 more |
||
| #VU76425 - Buffer Underwrite ('Buffer Underflow') CVE-2023-31130 |
CWE-124 | Low | 8.19.3-1.16.19.1.2.0.2, 9.5.0-1.18.14.2.3 | 23.05.2023 |
SB2023052309 SB2023052312 SB2023053021 and 55 more |
||
| #VU76424 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CVE-2023-31124 |
CWE-338 | Medium | 8.19.3-1.16.19.1.2.0.2, 9.5.0-1.18.14.2.3 | 23.05.2023 |
SB2023052309 SB2023052312 SB2023053021 and 33 more |
||
| #VU76423 - Improper input validation CVE-2023-32067 |
CWE-20 | Medium | 8.19.3-1.16.19.1.2.0.2, 9.5.0-1.18.14.2.3 | 23.05.2023 |
SB2023052312 SB2023053021 SB2023060711 and 35 more |
||
| #VU76422 - Improper input validation CVE-2023-32067 |
CWE-20 | Medium | 8.19.3-1.16.19.1.2.0.2, 9.5.0-1.18.14.2.3 | 23.05.2023 |
SB2023052309 SB2023052312 SB2023053021 and 66 more |
||
| #VU72750 - Inefficient Algorithmic Complexity CVE-2022-25881 |
CWE-407 | Medium | 6.14.18-1.14.21.3.1.0.1, 8.19.3-1.16.19.1.1.0.2 | 03.03.2023 |
SB2023030326 SB2023030328 SB2023031112 and 61 more |
||
| #VU72557 - Memory corruption CVE-2022-4904 |
CWE-119 | Low | 6.14.18-1.14.21.3.1.0.1, 8.19.3-1.16.19.1.1.0.2, 9.5.0-1.18.14.2.3 | 24.02.2023 |
SB2023022410 SB2023022502 SB2023030233 and 38 more |
||
| #VU72404 - Incorrect Regular Expression CVE-2023-24807 |
CWE-185 | Medium | 8.19.3-1.16.19.1.1.0.2 | 20.02.2023 |
SB2023022022 SB2023022020 SB2023030129 and 34 more |
||
| #VU72403 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2023-23936 |
CWE-113 | Medium | 8.19.3-1.16.19.1.1.0.2 | 20.02.2023 |
SB2023022022 SB2023022020 SB2023030129 and 35 more |
||
| #VU72400 - Permissions, Privileges, and Access Controls CVE-2023-23920 |
CWE-264 | Low | 6.14.18-1.14.21.3.1.0.1, 8.19.3-1.16.19.1.1.0.2 | 20.02.2023 |
SB2023022020 SB2023030129 SB2023030337 and 55 more |
||
| #VU59549 - Improper Validation of Certificate with Host Mismatch CVE-2021-44532 |
CWE-297 | Medium | 6.14.16-1.12.22.12.1 | 12.01.2022 |
SB2022011216 SB2022041522 SB2022042806 and 36 more |
Showing elements 41 - 60 out of 96