[admesh] Out-of-bounds read in admesh

ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-25033
https://github.com/admesh/admesh/issues…

[bignum] Uncaught Exception in bignum

All versions of the npm package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8. When verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.
References

h…