CVE-2018-5407Medium· 4.7▾ TwilightPoC availableSimultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 25.9 · likelihood 0.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.4%
Exploit-DB (last check)
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 18.10debian_linux = 8.0debian_linux = 9.0node.js < 6.14.4node.js >= 8.0.0, < 8.11.4node.js >= 10.0.0, < 10.9.0openssl >= 1.0.2, < 1.0.2qopenssl >= 1.1.0, < 1.1.0inessus < 8.1.1api_gateway = 11.1.2.4.0application_server = 0.9.8application_server = 1.0.0application_server = 1.0.1enterprise_manager_base_platform = 12.1.0.5.0enterprise_manager_base_platform = 13.2.0.0.0enterprise_manager_base_platform = 13.3.0.0.0enterprise_manager_ops_center = 12.3.3mysql_enterprise_backup <= 3.12.3mysql_enterprise_backup >= 3.12.4, <= 4.1.2peoplesoft_enterprise_peopletools = 8.55peoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57primavera_p6_enterprise_project_portfolio_management >= 17.7, <= 17.12primavera_p6_enterprise_project_portfolio_management = 8.4primavera_p6_enterprise_project_portfolio_management = 15.1primavera_p6_enterprise_project_portfolio_management = 15.2primavera_p6_enterprise_project_portfolio_management = 16.1primavera_p6_enterprise_project_portfolio_management = 16.2primavera_p6_enterprise_project_portfolio_management = 18.8tuxedo = 12.1.1.0.0vm_virtualbox < 6.0.0enterprise_linux_desktop = 7.0enterprise_linux_server = 7.0enterprise_linux_server = 7.6enterprise_linux_server_aus = 7.6enterprise_linux_server_eus = 7.6enterprise_linux_server_tus = 7.6enterprise_linux_workstation = 7.0Upgrade past the affected range:
node.js 10.9.0openssl 1.1.0inessus 8.1.1vm_virtualbox 6.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2018-12121High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed c…
CVE-2018-12122High· 7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated …
CVE-2018-12123Medium· 4.3Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed…
CVE-2018-12116High· 7.5Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will tr…
CVE-2018-12120High· 8.1Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default
CVE-2026-21710High· 7.5A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…