ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-36460
An issue was discovered in the model crate through 2020-11-10 for Rust.

An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type.

NVD description · AI analysis pending
8.11% PoC
  • model project model
CVE-2020-36255
An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0.

An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows an attacker to modify and forge authentication tokens.

NVD description · AI analysis pending
7.52%
  • identitymodel project identitymodel
CVE-2017-0374
+1 in the same advisory: …0373
lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working dir

lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.

NVD description · AI analysis pending
7.8
group max
<1%
  • config-model project config-model