isaacs
19 exploits
Active since Aug 2012
Node.js <0.6.17 & <0.7.8 - Info Disclosure
node-tar < 2.2.2 and 3.0.0-4.4.2 - Arbitrary File Overwrite via Hardlink Extraction
CVSS 7.5
node-tar < 2.2.2 and 3.0.0-4.4.2 - Arbitrary File Overwrite via Hardlink Extraction
CVSS 7.5
node-tar <6.1.1,5.0.6,4.4.14,3.3.2 - File Creation/Overwrite
CVSS 8.2
glob 10.2.0-10.4.9 and 11.0.0 - OS Command Injection via -c/--cmd Option
CVSS 7.5
tar < 7.5.3 - Arbitrary File Overwrite and Symlink Poisoning via Hardlink and SymbolicLink Entries
CVSS 6.1
tar < 7.5.10 - Path Traversal via Drive-Relative Hardlink
CVSS 6.3
tar < 7.5.11 - Path Traversal via Drive-Relative Symlink Target
CVSS 5.5
tar < 7.5.8 - Arbitrary File Read and Write via Hardlink Extraction
CVSS 7.1
minimatch < 10.2.1 - Regular Expression Denial of Service via Glob Pattern with Consecutive Wildcards
CVSS 7.5
Node Packaged Modules < 1.3.3 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
fstream < 1.0.12 - Arbitrary File Overwrite via Hardlink Extraction
CVSS 7.5
ini < 1.3.6 - Prototype Pollution via Malicious INI File Parsing
CVSS 7.3
node-tar <6.1.2-3.2.3 - File Creation/Overwrite
CVSS 8.2
minimatch < 3.0.5 - Denial of Service via braceExpand Function
CVSS 7.5
node-tar < 6.2.1 - Denial of Service via Excessive Sub-Folder Creation
CVSS 6.5
glob 10.2.0-10.4.9 and 11.0.0 - OS Command Injection via -c/--cmd Option
CVSS 7.5
node-tar <= 7.5.3 - Arbitrary File Overwrite via Unicode Path Collision Race Condition
CVSS 8.8
isaacs/tar < 7.5.7 - Path Traversal via Hardlink Entry Mismatch
CVSS 8.2