9.0.0
9 years ago
10 months ago
Known vulnerabilities in the org.webjars.npm:node-sass package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Buffer Overflow via the How to fix Buffer Overflow? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Denial of Service (DoS) via the How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Denial of Service (DoS) when executing the 'Sass::CompoundSelector::has_real_parent_ref' function in 'ast_selectors.cpp', which could lead to a stack overflow. How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Improper Certificate Validation. Certificate validation is disabled by default when requesting binaries, even if the user is not specifying an alternative download path. How to fix Improper Certificate Validation? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Denial of Service (DoS). Crafted objects passed to the How to fix Denial of Service (DoS)? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Denial of Service (DoS). Functions inside How to fix Denial of Service (DoS)? Upgrade | [,4.11.0) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-Bounds via How to fix Out-of-Bounds? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-bounds Read via How to fix Out-of-bounds Read? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Denial of Service (DoS). Uncontrolled recursion is possible in How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Denial of Service (DoS). The parsing component allows attackers to cause uncontrolled recursion in How to fix Denial of Service (DoS)? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-bounds Read via How to fix Out-of-bounds Read? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to NULL Pointer Dereference via the function How to fix NULL Pointer Dereference? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to NULL Pointer Dereference via How to fix NULL Pointer Dereference? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-bounds Read via the function How to fix Out-of-bounds Read? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Use After Free via the How to fix Use After Free? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-bounds Read. The function How to fix Out-of-bounds Read? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to NULL Pointer Dereference. The function How to fix NULL Pointer Dereference? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Uncontrolled Recursion via How to fix Uncontrolled Recursion? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-bounds Read via the function How to fix Out-of-bounds Read? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to NULL Pointer Dereference. An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function How to fix NULL Pointer Dereference? Upgrade | [,4.11.0) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Resource Exhaustion. In LibSass prior to 3.5.5, How to fix Resource Exhaustion? Upgrade | [,4.11.0) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Uncontrolled Recursion. There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service. How to fix Uncontrolled Recursion? Upgrade | [,4.11.0) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to NULL Pointer Dereference. In LibSass 3.5.5, a NULL Pointer Dereference in the function How to fix NULL Pointer Dereference? Upgrade | [,4.14.1) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-bounds Read. An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function How to fix Out-of-bounds Read? Upgrade | [,4.11.0) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to NULL Pointer Dereference in the function How to fix NULL Pointer Dereference? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Out-of-Bounds. A heap-based buffer over-read exists in How to fix Out-of-Bounds? There is no fixed version for | [0,) |
org.webjars.npm:node-sass is a Node.js bindings to libsass. Affected versions of this package are vulnerable to Use After Free. A use-after-free vulnerability exists in How to fix Use After Free? Upgrade | [,4.14.1) |