ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-25711
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file.

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

NVD description · AI analysis pending
7.5<1%
  • reproducible builds diffoscope
  • reproducible builds fedora
CVE-2017-0359
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

NVD description · AI analysis pending
9.82% PoC
  • reproducible builds diffoscope
  • reproducible builds debian linux