C2FO records
2 published records for vendor c2fo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-23561No exploit | All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.c2fo · comb · CWE-1321 | Critical9.8 | — | 1.2% | Dec 10, 2021 |
26Monitor | CVE-2020-26256No exploit | Denial of service in fast-csvc2fo · fast-csv · CWE-400 | Medium6.5 | — | 1.5% | Dec 8, 2020 |
- CVE-2021-2356139Monitor
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
CriticalCVSS 9.8No exploitEPSS 1%c2fo · combDec 10, 2021
- CVE-2020-2625626Monitor
Denial of service in fast-csv
MediumCVSS 6.5No exploitEPSS 2%c2fo · fast-csvDec 8, 2020