Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4055

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.035
EPSS Ranking 86.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 7.8
References
Products affected by CVE-2016-4055


Contact Us

Shodan ® - All rights reserved