RSS   Vulnerabilities for 'Moment'   RSS

2018-03-04
 
CVE-2017-18214

CWE-400
 

 
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

 
2017-01-23
 
CVE-2016-4055

CWE-399
 

 
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

 


Copyright 2024, cxsecurity.com

 

Back to Top