Security Vulnerabilities
- CVEs Published In August 2022
The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.
This affects all versions of package monorepo-build.
This affects all versions of package s3-kilatstorage.
This affects all versions of package curljs.
This affects all versions of package node-latex-pdf.
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
This affects the package image-tiler before 2.0.2.
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.