A vulnerability was found in C4B OBD-II Dongle 2.x/3.4.x. It has been rated as critical. This issue affects some unknown processing of the component SSH Key. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2015-2906. The attack may be initiated remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
A vulnerability classified as problematic was found in send Package up to 0.11.0 on Node.js. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure (Path).
This vulnerability is known as CVE-2015-8859. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.