CWE-506

Embedded Malicious Code

Parent: CWE-912 - Hidden Functionality

The product contains code that appears to be malicious in nature.

85 vulnerabilities with CWE-506
CVE-2017-16051 HIGH
sqliter - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
CVE-2017-16050 HIGH
sqlite.js - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
CVE-2017-16049 HIGH
nodesqlite - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
CVE-2017-16048 HIGH
node-sqlite - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
CVE-2017-16046 HIGH
npm mariadb - Embedded Malicious Code
CVSS 7.5
CVE-2017-16045 HIGH
jquery.js - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
CVE-2017-16044 HIGH
D3.js - Information Disclosure
CVSS 7.5
CVE-2017-16062 HIGH
node-tkinter - Exposure of Sensitive Information via Environment Variable Hijacking
CVSS 7.5
CVE-2017-16061 HIGH
tkinter - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
CVE-2017-16047 HIGH
mysqljs - Exposure of Sensitive Information via Malicious Environment Variable Hijacking
CVSS 7.5
Details
Vulnerabilities 85