ZeroHour

CVE-2016-10578

CVSS 3.0
8.1 high
EPSS
<1%p46
Published
()
Modified
Description

unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.

Vendors
unicode project
Products
unicode
Weakness
CWE-311, CWE-310
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.