Known vulnerabilities in npm - page 4
Vendor:
OpenAnolis
Software:
npm
Software CPE:
cpe:2.3:o:openanolis:npm:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
96
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
10.8.2-1.20.20.2.1
10.8.2-1.20.20.0.1
10.8.2-1.20.19.2.1
10.8.2-1.20.19.1.1
10.8.1-1.20.16.0.1
8.19.3-1.16.19.1.2.0.2
9.5.0-1.18.14.2.3
6.14.17-1.14.21.1.2.0.1
6.14.15-1.14.18.2.2
6.14.14-1.14.17.5.1
6.14.14-1.12.22.5.1
10.8.2-1.18.20.6.1
10.8.2-1.20.18.2.1
10.7.0-1.18.20.4.1
10.5.0-1.18.20.2.1.0.1
8.19.4-1.16.20.2.4.0.1
10.2.4-1.18.19.1.1.0.1
8.19.4-1.16.20.2.3.0.2
9.8.1-1.18.18.2.1.0.1
9.6.7-1.18.17.1.1.0.2
8.19.4-1.16.20.2.2.0.2
9.5.1-1.18.16.1.1
8.19.4-1.16.20.1.1.0.1
8.19.3-1.16.19.1.1.0.2
6.14.18-1.14.21.3.1.0.1
8.19.1-1.18.9.1.1
8.15.0-1.16.17.1.1
8.11.0-1.16.16.0.3
6.14.17-1.14.20.0.2
6.14.16-1.12.22.12.1
8.1.2-1.16.13.1.3
6.14.13-1.12.22.3.2
6.14.13-1.14.17.3.2
Vulnerabilities (96)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU72399 - Resource Management Errors CVE-2023-23919 |
CWE-399 | Medium | 8.19.3-1.16.19.1.1.0.2 | 20.02.2023 |
SB2023022020 SB2023030129 SB2023030337 and 33 more |
||
| #VU72398 - Permissions, Privileges, and Access Controls CVE-2023-23918 |
CWE-264 | Medium | 6.14.18-1.14.21.3.1.0.1, 8.19.3-1.16.19.1.1.0.2 | 20.02.2023 |
SB2023022020 SB2023030129 SB2023030337 and 48 more |
||
| #VU72247 - Improper input validation CVE-2022-38900 |
CWE-20 | Medium | 6.14.18-1.14.21.3.1.0.1 | 15.02.2023 |
SB2023021531 SB2023022714 SB2023032315 and 35 more |
||
| #VU69942 - Incorrect Regular Expression CVE-2022-3517 |
CWE-185 | Medium | 6.14.17-1.14.21.1.2.0.1, 6.14.18-1.14.21.3.1.0.1 | 06.12.2022 |
SB2022120638 SB2022120639 SB2022120640 and 50 more |
||
| #VU69675 - Improper Control of Generation of Code ('Code Injection') CVE-2022-24999 |
CWE-94 | Medium | 6.14.17-1.14.21.1.2.0.1 | 29.11.2022 |
SB2022112910 SB2022112911 SB2022112943 and 50 more |
||
| #VU69354 - Reliance on Reverse DNS Resolution for a Security-Critical Action CVE-2022-43548 |
CWE-350 | Medium | 6.14.17-1.14.21.1.2.0.1 | 15.11.2022 |
SB2022111599 SB20221115101 SB20221115102 and 47 more |
||
| #VU67850 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-35256 |
CWE-444 | Medium | 8.15.0-1.16.17.1.1, 8.19.1-1.18.9.1.1 | 03.10.2022 |
SB2022100347 SB2022100401 SB2022100402 and 50 more |
||
| #VU67849 - Use of Insufficiently Random Values CVE-2022-35255 |
CWE-330 | Medium | 8.15.0-1.16.17.1.1, 8.19.1-1.18.9.1.1 | 03.10.2022 |
SB2022100401 SB2022100402 SB2022100528 and 40 more |
||
| #VU66955 - Improper Control of Generation of Code ('Code Injection') CVE-2020-7788 |
CWE-94 | Medium | 6.14.15-1.14.18.2.2, 8.1.2-1.16.13.1.3 | 05.09.2022 |
SB2020121120 SB2022090501 SB2022091209 and 21 more |
||
| #VU66400 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2022-33987 |
CWE-601 | Medium | 6.14.17-1.14.20.0.2, 8.11.0-1.16.16.0.3 | 11.08.2022 |
SB2022081124 SB2022081525 SB2022090835 and 22 more |
||
| #VU65282 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-32215 |
CWE-444 | Medium | 6.14.17-1.14.20.0.2, 8.11.0-1.16.16.0.3 | 13.07.2022 |
SB2022071338 SB2022071610 SB2022071611 and 54 more |
||
| #VU65278 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-32214 |
CWE-444 | Medium | 6.14.17-1.14.20.0.2, 8.11.0-1.16.16.0.3 | 13.07.2022 |
SB2022071338 SB2022071610 SB2022071611 and 36 more |
||
| #VU65275 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-32213 |
CWE-444 | Medium | 6.14.17-1.14.20.0.2, 8.11.0-1.16.16.0.3 | 13.07.2022 |
SB2022071338 SB2022071610 SB2022071611 and 55 more |
||
| #VU65273 - Improper Check or Handling of Exceptional Conditions CVE-2022-32212 |
CWE-703 | Medium | 6.14.17-1.14.20.0.2, 6.14.17-1.14.21.1.2.0.1, 8.11.0-1.16.16.0.3 | 13.07.2022 |
SB2022071338 SB2022071610 SB2022071611 and 48 more |
||
| #VU64030 - Resource exhaustion CVE-2021-44906 |
CWE-400 | High | 6.14.17-1.14.21.1.2.0.1 | 07.06.2022 |
SB2022060836 SB2022062103 SB2022062203 and 53 more |
||
| #VU61471 - Exposure of sensitive information to an unauthorized actor CVE-2022-0235 |
CWE-200 | Low | 6.14.17-1.14.21.1.2.0.1 | 20.03.2022 |
SB2022032001 SB2022032002 SB2022032009 and 35 more |
||
| #VU59234 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-22960 |
CWE-444 | Medium | 6.14.15-1.14.18.2.2, 8.1.2-1.16.13.1.3 | 05.01.2022 |
SB2022010523 SB2022010524 SB2022042806 and 40 more |
||
| #VU59233 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-22959 |
CWE-444 | Medium | 6.14.15-1.14.18.2.2, 8.1.2-1.16.13.1.3 | 05.01.2022 |
SB2022010523 SB2022010524 SB2022011841 and 43 more |
||
| #VU55102 - Resource exhaustion CVE-2021-35065 |
CWE-400 | Medium | 6.14.18-1.14.21.3.1.0.1, 8.19.3-1.16.19.1.1.0.2 | 21.07.2021 |
SB2021072101 SB2023020668 SB2023020971 and 24 more |
||
| #VU52985 - Incorrect Regular Expression CVE-2020-28469 |
CWE-185 | Medium | 6.14.15-1.14.18.2.2, 8.1.2-1.16.13.1.3 | 10.05.2021 |
SB2021051002 SB2021051004 SB2021072625 and 26 more |
Showing elements 61 - 80 out of 96