Dart records
14 published records for vendor dart.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-284 Improper Access Control1
- CWE-305 Authentication Bypass by Primary Weakness1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2008-4652Proof of concept | Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execdart · powertcp ftp for activex · CWE-119 | Critical9.3 | — | 10.1% | Oct 21, 2008 |
39Monitor | CVE-2007-2856Proof of concept | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is useddart · powertcp zip compression · CWE-119 | Critical9.3 | — | 7.2% | May 24, 2007 |
39Monitor | CVE-2022-3095No exploit | Incorrect parsing of the backslash characters in Dart librarydart · dart software development kit · CWE-20 | Critical9.8 | — | 0.9% | Oct 27, 2022 |
38Monitor | CVE-2007-2855No exploit | Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote dart · dart ziplite compression · CWE-119 | Critical9.3 | — | 4.8% | May 24, 2007 |
35Monitor | CVE-2021-22568No exploit | Dart - Publishing to third-party package repositories may expose pub.dev credentialsdart · dart software development kit · CWE-255 | High8.8 | — | 0.9% | Dec 9, 2021 |
32Monitor | CVE-2012-5389No exploit | NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (applicatidart · powertcp webserver for activex · CWE-476 | High7.5 | — | 6.6% | Jan 23, 2020 |
26Monitor | CVE-2022-0451No exploit | Auth bypass in Dark SDKdart · dart software development kit · CWE-305 | Medium6.5 | — | 1.0% | Feb 18, 2022 |
26Monitor | CVE-2026-27704No exploit | Dart SDK and Flutter SDK have Zip slip in Dart Pub package extractiondart · dart software development kit · CWE-22 | Medium6.6 | — | 0.5% | Feb 25, 2026 |
25Monitor | CVE-2020-35669Proof of concept | An issue was discovered in the http package through 0.12.2 for Dart.dart · http · CWE-74 | Medium6.1 | — | 2.2% | Dec 23, 2020 |
24Monitor | CVE-2021-22540No exploit | Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.dart · dart software development kit · CWE-79 | Medium6.1 | — | 0.7% | Apr 22, 2021 |
24Monitor | CVE-2014-125098No exploit | Dart http_server Directory Listing virtual_directory.dart VirtualDirectory cross site scriptingdart · http server · CWE-79 | Medium6.1 | — | 0.6% | Apr 10, 2023 |
24Monitor | CVE-2020-8923No exploit | An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM dart · dart software development kit · CWE-79 | Medium6.1 | — | 0.3% | Mar 26, 2020 |
21Monitor | CVE-2012-3819Proof of concept | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, alldart · powertcp activex · CWE-119 | Medium5.0 | — | 2.3% | Oct 4, 2012 |
14Monitor | CVE-2021-22567No exploit | Bidirectional Override in Dart SDKdart · dart software development kit · CWE-284 | Low3.5 | — | 0.6% | Jan 5, 2022 |
- CVE-2008-465240Plan
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to exec
CriticalCVSS 9.3Proof of conceptEPSS 10%dart · powertcp ftp for activexOct 21, 2008
- CVE-2007-285639Monitor
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used
CriticalCVSS 9.3Proof of conceptEPSS 7%dart · powertcp zip compressionMay 24, 2007
- CVE-2022-309539Monitor
Incorrect parsing of the backslash characters in Dart library
CriticalCVSS 9.8No exploitEPSS 1%dart · dart software development kitOct 27, 2022
- CVE-2007-285538Monitor
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote
CriticalCVSS 9.3No exploitEPSS 5%dart · dart ziplite compressionMay 24, 2007
- CVE-2021-2256835Monitor
Dart - Publishing to third-party package repositories may expose pub.dev credentials
HighCVSS 8.8No exploitEPSS 1%dart · dart software development kitDec 9, 2021
- CVE-2012-538932Monitor
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (applicati
HighCVSS 7.5No exploitEPSS 7%dart · powertcp webserver for activexJan 23, 2020
- CVE-2022-045126Monitor
Auth bypass in Dark SDK
MediumCVSS 6.5No exploitEPSS 1%dart · dart software development kitFeb 18, 2022
- CVE-2026-2770426Monitor
Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction
MediumCVSS 6.6No exploitEPSS 1%dart · dart software development kitFeb 25, 2026
- CVE-2020-3566925Monitor
An issue was discovered in the http package through 0.12.2 for Dart.
MediumCVSS 6.1Proof of conceptEPSS 2%dart · httpDec 23, 2020
- CVE-2021-2254024Monitor
Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.
MediumCVSS 6.1No exploitEPSS 1%dart · dart software development kitApr 22, 2021
- CVE-2014-12509824Monitor
Dart http_server Directory Listing virtual_directory.dart VirtualDirectory cross site scripting
MediumCVSS 6.1No exploitEPSS 1%dart · http serverApr 10, 2023
- CVE-2020-892324Monitor
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM
MediumCVSS 6.1No exploitEPSS 0%dart · dart software development kitMar 26, 2020
- CVE-2012-381921Monitor
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, all
MediumCVSS 5.0Proof of conceptEPSS 2%dart · powertcp activexOct 4, 2012
- CVE-2021-2256714Monitor
Bidirectional Override in Dart SDK
LowCVSS 3.5No exploitEPSS 1%dart · dart software development kitJan 5, 2022