Total vulnerabilities in the database
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
Software | From | Fixed in |
---|---|---|
nodejs / node.js | 15.0.0 | 15.2.1 |
nodejs / node.js | 14.13.0 | 14.15.1 |
nodejs / node.js | 12.16.3 | 12.19.1 |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
oracle / graalvm | 19.3.4 | 19.3.4.x |
oracle / graalvm | 20.3.0 | 20.3.0.x |
oracle / retail_xstore_point_of_service | 16.0.6 | 16.0.6.x |
oracle / retail_xstore_point_of_service | 17.0.4 | 17.0.4.x |
oracle / retail_xstore_point_of_service | 18.0.3 | 18.0.3.x |
oracle / retail_xstore_point_of_service | 19.0.2 | 19.0.2.x |
oracle / jd_edwards_enterpriseone_tools | - | 9.2.6.0 |
oracle / mysql_cluster | - | 8.0.23.x |
oracle / blockchain_platform | - | 21.1.2 |
c-ares_project / c-ares | - | 1.16.0 |