Skip to content
Noroxi

minecraft records

4 published records for vendor minecraft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

4 records
  • The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as p

    CriticalCVSS 9.8No exploitEPSS 3%

    techreborn · reborncoreMay 31, 2021

  • Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    minecraft · bedrock serverMar 28, 2022

  • Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world

    HighCVSS 8.8No exploitEPSS 1%

    minecraft · minecraftMay 30, 2023

  • Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.

    HighCVSS 7.5No exploitEPSS 1%

    minecraft · minecraftJul 20, 2021