CWE-433
3 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-433page 1 of 1
- CVE-2017-16061HIGHCVSS 7.5EG 7.52018-05-29
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16065HIGHCVSS 7.5EG 7.52018-06-07
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16070HIGHCVSS 7.5EG 7.52018-06-07
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Map vulnerabilities like CWE-433 to your infrastructure
EchelonGraph correlates every CVE — across CWE-433 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →