ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27390
+1 in the same advisory: …31194
A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139.

A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

NVD description · AI analysis pending
7.8<1% PoC
  • diagon project diagon
CVE-2020-25739
An issue was discovered in the gon gem before gon-6.4.0 for Ruby.

An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.

NVD description · AI analysis pending
6.11%
  • gon project gon
  • gon project ubuntu linux
  • gon project debian linux