4.3
CVSSv2

CVE-2016-7099

Published: 10/10/2016 Updated: 05/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 391
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The tls.checkServerIdentity function in Node.js 0.10.x prior to 0.10.47, 0.12.x prior to 0.12.16, 4.x prior to 4.6.0, and 6.x prior to 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle malicious users to spoof servers via a crafted certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs node.js 0.10.44

nodejs node.js 0.10.45

nodejs node.js 0.10.40

nodejs node.js 0.10.4

nodejs node.js 0.10.33

nodejs node.js 0.10.32

nodejs node.js 0.10.26

nodejs node.js 0.10.25

nodejs node.js 0.10.18

nodejs node.js 0.10.17

nodejs node.js 0.10.11

nodejs node.js 0.10.10

nodejs node.js 0.10.8

nodejs node.js 0.10.7

nodejs node.js 0.10.6

nodejs node.js 0.10.37

nodejs node.js 0.10.36

nodejs node.js 0.10.3

nodejs node.js 0.10.29

nodejs node.js 0.10.21

nodejs node.js 0.10.20

nodejs node.js 0.10.15

nodejs node.js 0.10.14

nodejs node.js 0.10.42

nodejs node.js 0.10.43

nodejs node.js 0.10.5

nodejs node.js 0.10.41

nodejs node.js 0.10.35

nodejs node.js 0.10.34

nodejs node.js 0.10.28

nodejs node.js 0.10.27

nodejs node.js 0.10.2

nodejs node.js 0.10.19

nodejs node.js 0.10.13

nodejs node.js 0.10.12

nodejs node.js 0.10.46

nodejs node.js 0.10.9

nodejs node.js 0.10.39

nodejs node.js 0.10.38

nodejs node.js 0.10.31

nodejs node.js 0.10.30

nodejs node.js 0.10.24

nodejs node.js 0.10.23

nodejs node.js 0.10.22

nodejs node.js 0.10.16-isaacs-manual

nodejs node.js 0.10.16

nodejs node.js 0.10.1

nodejs node.js 0.10.0

suse linux enterprise 12.0

nodejs node.js 6.2.0

nodejs node.js 6.2.1

nodejs node.js 6.4.0

nodejs node.js 6.5.0

nodejs node.js 6.1.0

nodejs node.js 6.6.0

nodejs node.js 6.0.0

nodejs node.js 6.2.2

nodejs node.js 6.3.0

nodejs node.js 6.3.1

nodejs node.js 0.12.10

nodejs node.js 0.12.8

nodejs node.js 0.12.7

nodejs node.js 0.12.0

nodejs node.js 0.12.13

nodejs node.js 0.12.14

nodejs node.js 0.12.4

nodejs node.js 0.12.3

nodejs node.js 0.12.15

nodejs node.js 0.12.9

nodejs node.js 0.12.2

nodejs node.js 0.12.1

nodejs node.js 0.12.11

nodejs node.js 0.12.12

nodejs node.js 0.12.6

nodejs node.js 0.12.5

nodejs node.js 4.3.0

nodejs node.js 4.4.4

nodejs node.js 4.4.5

nodejs node.js 4.2.3

nodejs node.js 4.2.2

nodejs node.js 4.4.0

nodejs node.js 4.4.1

nodejs node.js 4.5.0

nodejs node.js 4.2.6

nodejs node.js 4.1.2

nodejs node.js 4.1.1

nodejs node.js 4.4.2

nodejs node.js 4.4.3

nodejs node.js 4.2.5

nodejs node.js 4.2.4

nodejs node.js 4.1.0

nodejs node.js 4.0.0

nodejs node.js 4.3.1

nodejs node.js 4.3.2

nodejs node.js 4.4.6

nodejs node.js 4.4.7

nodejs node.js 4.2.1

nodejs node.js 4.2.0

Vendor Advisories

Synopsis Important: rh-nodejs4-nodejs and rh-nodejs4-http-parser security update Type/Severity Security Advisory: Important Topic An update for rh-nodejs4-nodejs and rh-nodejs4-http-parser is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security i ...
Debian Bug report logs - #839714 CVE-2016-5325 / CVE-2016-7099 Package: src:nodejs; Maintainer for src:nodejs is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 4 Oct 2016 09:15:01 UTC Severity: grave Tags: security Fixed in v ...
The tlscheckServerIdentity function in Nodejs 010x before 01047, 012x before 01216, 4x before 460, and 6x before 670 does not properly handle wildcards in name fields of X509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate ...

Github Repositories

node as shared-library

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine Nodejs uses an event-driven, non-blocking I/O model that makes it lightweight and efficient The Nodejs package ecosystem, npm, is the largest ecosystem of open source libraries in the world The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed

My Discord Bot

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

npmreadme Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Rel

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine Nodejs uses an event-driven, non-blocking I/O model that makes it lightweight and efficient The Nodejs package ecosystem, npm, is the largest ecosystem of open source libraries in the world The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

este es otra version del proyecto final pero con ventanas tipo modal

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

speed up nodejs booting using snapshot

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine Nodejs uses an event-driven, non-blocking I/O model that makes it lightweight and efficient The Nodejs package ecosystem, npm, is the largest ecosystem of open source libraries in the world The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed

Second phase 3.

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

el ejemplo que hemos estado haciendo en clase de laboratorio de computacion para UTN

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

DebugAwait function, which facilities debugging of unfinished awaits and unawaited promises from async functions.

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine Nodejs uses an event-driven, non-blocking I/O model that makes it lightweight and efficient The Nodejs package ecosystem, npm, is the largest ecosystem of open source libraries in the world The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed

外包项目

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

A fork of Node.js. Humans before technology.

Ayojs (Note: Ayojs is forked from Nodejs Currently, a lot of the documentation still points towards the Nodejs repository) Ayojs is a JavaScript runtime built on Chrome's V8 JavaScript engine It uses an event-driven, non-blocking I/O model that makes it lightweight and efficient Ayojs, like the rest of the JavaScript implementations, benefits from the npm packag

Tracer extension to V8 in node.js.

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project uses an open governance model The Nodejs Foundation provides support for the project This project is bound by a Code of Conduct Table of Contents Support Release Types Download Current and LTS Releases Nightly Re

Nodejs is a JavaScript runtime built on Chrome's V8 JavaScript engine For more information on using Nodejs, see the Nodejs Website The Nodejs project is supported by the Nodejs Foundation Contributions, policies, and releases are managed under an open governance model This project is bound by a Code of Conduct Table of Contents Support Release Types Download C