7.5
CVSSv2

CVE-2017-16042

Published: 04/06/2018 Updated: 09/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Growl adds growl notification support to nodejs. Growl prior to 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

growl project growl

Vendor Advisories

Debian Bug report logs - #900868 node-growl: CVE-2017-16042: Does not properly sanitize input before passing it to exec Package: src:node-growl; Maintainer for src:node-growl is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed ...

Github Repositories

Mirror of https://gitlab.com/aviortheking/code-stats-vscode

Code::Stats extension to Visual Studio Code This is a Visual Studio Code extension to send updates to codestatsnet Note This is a fork that will try stay up to date with VSCode and available on open-vsxorg Features This extension tracks the amount of changes you make to your files and sends out pulses to codestatsnet/api-docs#pulse to track your XP Extensio