Package impact

npm npm / ms

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-8315 high 7.5 7.5 10y ago The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
CVE-2017-20162 unknown 3y ago Vercel ms Inefficient Regular Expression Complexity vulnerability