All CVEs — page 198 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This flaw allows attackers to replace the process-wide certificate authorities in NodeVM sandbox code, enabling them to accept attacker-controlled certificates. This can lead to unauthorized access to secure communications.
This flaw allows sandboxed code to access and manipulate host HTTPS requests, enabling credential theft and unauthorized request issuance.
This flaw allows sandboxed JavaScript to escape the NodeVM sandbox by calling the crypto.setEngine() method with a filesystem path to an attacker-supplied native library, leading to arbitrary code execution.
This flaw allows sandboxed code to execute arbitrary native code outside the sandbox with host process privileges by leveraging the Node.js sqlite module.
The flaw allows untrusted code in the sandbox to obtain a fully functional proxy to a host object, enabling arbitrary command execution with host process privileges.
The flaw allows an attacker to escape the sandbox by supplying a specific configuration to the NodeVM constructor, thereby executing arbitrary commands with the host process's privileges.
This flaw allows attackers to bypass sandbox restrictions and execute arbitrary code, posing a critical risk to system security.