Skip to main content

Vendor archive

umbraengineering CVEs

Beta · best-effort

2 CVEs tagged to vendor umbraengineering2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2018-16460

Published Sep 7, 2018

A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-3751

Published Jul 3, 2018

The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1