0.9.12
5 years ago
25 days ago
Known vulnerabilities in the @xmldom/xmldom package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection via the How to fix XML Injection? Upgrade | >=0.7.0 <0.8.14>=0.9.0-beta.1 <0.9.11 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | >=0.7.0 <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection via the How to fix XML Injection? Upgrade | >=0.7.0 <0.8.14>=0.9.0-beta.1 <0.9.11 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the Note: This is only exploitable if the application explicitly creates and serializes an How to fix Improper Encoding or Escaping of Output? Upgrade | >=0.7.0 <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the How to fix Inefficient Algorithmic Complexity? Upgrade | >=0.7.0 <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection in the How to fix XML Injection? Upgrade | >=0.7.0 <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | >=0.7.0 <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | >=0.7.0 <0.8.15 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input via the How to fix Improper Validation of Syntactic Correctness of Input? Upgrade | >=0.7.0 <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection via improper validation of the How to fix XML Injection? Upgrade | <0.8.15>=0.9.0-beta.1 <0.9.12 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection via the Note: This is only exploitable if the serialization is performed without passing the How to fix XML Injection? Upgrade | <0.8.13>=0.9.0 <0.9.10 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection in the serialization of Note: This is only exploitable if untrusted data is passed programmatically to How to fix XML Injection? Upgrade | <0.8.13>=0.9.0 <0.9.10 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Uncontrolled Recursion in the recursive processing of deeply nested XML documents by several DOM-related operations, including How to fix Uncontrolled Recursion? Upgrade | <0.8.13>=0.9.0 <0.9.10 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection due to unvalidated comment serialization. When an application uses the package to create an XML comment from untrusted user input, the package fails to sanitize comment-breaking sequences (like How to fix XML Injection? Upgrade | <0.8.13>=0.9.0 <0.9.10 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to XML Injection via the How to fix XML Injection? Upgrade | <0.8.12>=0.9.0 <0.9.9 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Improper Input Validation due to parsing XML that is not well-formed, and contains multiple top-level elements. All the root nodes are being added to the How to fix Improper Input Validation? Upgrade | <0.7.7>=0.8.0 <0.8.4>=0.9.0-beta.1 <0.9.0-beta.4 |
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom Affected versions of this package are vulnerable to Prototype Pollution through the DISPUTED This vulnerability has been disputed by the maintainers of the package. Currently the only viable exploit that has been demonstrated is to pollute the target object (rather then the global object which is generally the case for Prototype Pollution vulnerabilities) and it is yet unclear if this limited attack vector exposes any vulnerability in the context of this package. See the linked GitHub Issue for full details on the discussion around the legitimacy and potential revocation of this vulnerability. How to fix Prototype Pollution? Upgrade | <0.7.6>=0.8.0 <0.8.3>=0.9.0-beta.1 <0.9.0-beta.2 |