ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-31579
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

NVD description · AI analysis pending
9.31%
  • iasset project iasset
CVE-2022-21231
All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function.

All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)

NVD description · AI analysis pending
9.81% PoC
  • deep-get-set project deep-get-set
CVE-2022-25645
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if t

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

NVD description · AI analysis pending
8.12% PoC ×2
  • dset project dset
CVE-2021-23497
This affects the package @strikeentco/set before 1.0.2.

This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821

NVD description · AI analysis pending
9.84% PoC
  • set project set
CVE-2021-25952
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code ex

Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.

NVD description · AI analysis pending
9.83% PoC
  • just-safe-set project just-safe-set
CVE-2021-25915
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execut

Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.

NVD description · AI analysis pending
9.84% PoC
  • changeset project changeset
CVE-2020-28277
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

NVD description · AI analysis pending
9.83% PoC ×2
  • dset project dset
CVE-2020-28276
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

NVD description · AI analysis pending
9.83% PoC ×2
  • deep-set project deep-set
CVE-2020-28267
Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

NVD description · AI analysis pending
7.52%
  • set project set
CVE-2020-7715
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.

All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.

NVD description · AI analysis pending
9.82% PoC
  • deep-get-set project deep-get-set
CVE-2019-15553
An issue was discovered in the memoffset crate before 0.5.0 for Rust.

An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.

NVD description · AI analysis pending
7.52%
  • memoffset project memoffset
CVE-2017-16098
charset 1.0.0 and below are vulnerable to regular expression denial of service.

charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.

NVD description · AI analysis pending
7.52% PoC
  • charset project charset
CVE-2016-10663
wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.

wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

NVD description · AI analysis pending
8.12%
  • node-wixtoolset project node-wixtoolset