trailofbits records
12 published records for vendor trailofbits.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-184 Incomplete List of Disallowed Inputs6
- CWE-295 Improper Certificate Validation1
- CWE-325 Missing Cryptographic Step1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-502 Deserialization of Untrusted Data1
- CWE-693 Protection Mechanism Failure1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-39969No exploit | uthenticode signature validation bypass vulnerabilitytrailofbits · uthenticode · CWE-347 | Critical9.8 | — | 0.6% | Aug 9, 2023 |
39Monitor | CVE-2026-14535No exploit | Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()trailofbits · fickling · CWE-693 | Critical9.8 | — | 0.6% | Jul 4, 2026 |
35Monitor | CVE-2026-22609No exploit | Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklisttrailofbits · fickling · CWE-184 | High8.9 | — | 0.6% | Jan 9, 2026 |
35Monitor | CVE-2026-14534No exploit | Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)trailofbits · fickling · CWE-184 | High8.8 | — | 0.6% | Jul 4, 2026 |
35Monitor | CVE-2026-22607No exploit | Fickling Blocklist Bypass: cProfile.run()trailofbits · fickling · CWE-184 | High8.9 | — | 0.5% | Jan 9, 2026 |
35Monitor | CVE-2026-22606No exploit | Fickling has a bypass via runpy.run_path() and runpy.run_module()trailofbits · fickling · CWE-184 | High8.9 | — | 0.5% | Jan 9, 2026 |
35Monitor | CVE-2026-22608No exploit | Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detectiontrailofbits · fickling · CWE-184 | High8.9 | — | 0.4% | Jan 9, 2026 |
35Monitor | CVE-2026-22612No exploit | Fickling vulnerable to detection bypass due to "builtins" blindnesstrailofbits · fickling · CWE-502 | High8.9 | — | 0.3% | Jan 9, 2026 |
30Monitor | CVE-2023-40012No exploit | uthenticode EKU validation bypasstrailofbits · uthenticode · CWE-325 | High7.5 | — | 0.2% | Aug 9, 2023 |
30Monitor | CVE-2026-33753No exploit | Improper Certificate Validation in rfc3161-clienttrailofbits · rfc3161-client · CWE-295 | High7.5 | — | 0.2% | Apr 8, 2026 |
28Monitor | CVE-2025-67747No exploit | Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules listtrailofbits · fickling · CWE-184 | High7.1 | — | 0.3% | Dec 15, 2025 |
28Monitor | CVE-2025-67748No exploit | Fickling has Code Injection vulnerability via pty.spawn()trailofbits · fickling · CWE-94 | High7.1 | — | 0.3% | Dec 15, 2025 |
- CVE-2023-3996939Monitor
uthenticode signature validation bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 1%trailofbits · uthenticodeAug 9, 2023
- CVE-2026-1453539Monitor
Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()
CriticalCVSS 9.8No exploitEPSS 1%trailofbits · ficklingJul 4, 2026
- CVE-2026-2260935Monitor
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
HighCVSS 8.9No exploitEPSS 1%trailofbits · ficklingJan 9, 2026
- CVE-2026-1453435Monitor
Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)
HighCVSS 8.8No exploitEPSS 1%trailofbits · ficklingJul 4, 2026
- CVE-2026-2260735Monitor
Fickling Blocklist Bypass: cProfile.run()
HighCVSS 8.9No exploitEPSS 1%trailofbits · ficklingJan 9, 2026
- CVE-2026-2260635Monitor
Fickling has a bypass via runpy.run_path() and runpy.run_module()
HighCVSS 8.9No exploitEPSS 0%trailofbits · ficklingJan 9, 2026
- CVE-2026-2260835Monitor
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
HighCVSS 8.9No exploitEPSS 0%trailofbits · ficklingJan 9, 2026
- CVE-2026-2261235Monitor
Fickling vulnerable to detection bypass due to "builtins" blindness
HighCVSS 8.9No exploitEPSS 0%trailofbits · ficklingJan 9, 2026
- CVE-2023-4001230Monitor
uthenticode EKU validation bypass
HighCVSS 7.5No exploitEPSS 0%trailofbits · uthenticodeAug 9, 2023
- CVE-2026-3375330Monitor
Improper Certificate Validation in rfc3161-client
HighCVSS 7.5No exploitEPSS 0%trailofbits · rfc3161-clientApr 8, 2026
- CVE-2025-6774728Monitor
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
HighCVSS 7.1No exploitEPSS 0%trailofbits · ficklingDec 15, 2025
- CVE-2025-6774828Monitor
Fickling has Code Injection vulnerability via pty.spawn()
HighCVSS 7.1No exploitEPSS 0%trailofbits · ficklingDec 15, 2025