Записи Dart
14 опубликованных записей вендора dart.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 14,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-284 Improper Access Control1
- CWE-305 Authentication Bypass by Primary Weakness1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2008-4652Proof of concept | Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execdart · powertcp ftp for activex · CWE-119 | Критическая9,3 | — | 10,1 % | 21 окт. 2008 г. |
39Наблюдать | CVE-2007-2856Proof of concept | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is useddart · powertcp zip compression · CWE-119 | Критическая9,3 | — | 7,2 % | 24 мая 2007 г. |
39Наблюдать | CVE-2022-3095Эксплойта нет | Incorrect parsing of the backslash characters in Dart librarydart · dart software development kit · CWE-20 | Критическая9,8 | — | 0,9 % | 27 окт. 2022 г. |
38Наблюдать | CVE-2007-2855Эксплойта нет | Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote dart · dart ziplite compression · CWE-119 | Критическая9,3 | — | 4,8 % | 24 мая 2007 г. |
35Наблюдать | CVE-2021-22568Эксплойта нет | Dart - Publishing to third-party package repositories may expose pub.dev credentialsdart · dart software development kit · CWE-255 | Высокая8,8 | — | 0,9 % | 9 дек. 2021 г. |
32Наблюдать | CVE-2012-5389Эксплойта нет | NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (applicatidart · powertcp webserver for activex · CWE-476 | Высокая7,5 | — | 6,6 % | 23 янв. 2020 г. |
26Наблюдать | CVE-2022-0451Эксплойта нет | Auth bypass in Dark SDKdart · dart software development kit · CWE-305 | Средняя6,5 | — | 1,0 % | 18 февр. 2022 г. |
26Наблюдать | CVE-2026-27704Эксплойта нет | Dart SDK and Flutter SDK have Zip slip in Dart Pub package extractiondart · dart software development kit · CWE-22 | Средняя6,6 | — | 0,5 % | 25 февр. 2026 г. |
25Наблюдать | CVE-2020-35669Proof of concept | An issue was discovered in the http package through 0.12.2 for Dart.dart · http · CWE-74 | Средняя6,1 | — | 2,2 % | 23 дек. 2020 г. |
24Наблюдать | CVE-2021-22540Эксплойта нет | Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.dart · dart software development kit · CWE-79 | Средняя6,1 | — | 0,7 % | 22 апр. 2021 г. |
24Наблюдать | CVE-2014-125098Эксплойта нет | Dart http_server Directory Listing virtual_directory.dart VirtualDirectory cross site scriptingdart · http server · CWE-79 | Средняя6,1 | — | 0,6 % | 10 апр. 2023 г. |
24Наблюдать | CVE-2020-8923Эксплойта нет | An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM dart · dart software development kit · CWE-79 | Средняя6,1 | — | 0,3 % | 26 мар. 2020 г. |
21Наблюдать | CVE-2012-3819Proof of concept | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, alldart · powertcp activex · CWE-119 | Средняя5,0 | — | 2,3 % | 4 окт. 2012 г. |
14Наблюдать | CVE-2021-22567Эксплойта нет | Bidirectional Override in Dart SDKdart · dart software development kit · CWE-284 | Низкая3,5 | — | 0,6 % | 5 янв. 2022 г. |
- CVE-2008-465240В плане
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to exec
КритическаяCVSS 9,3Proof of conceptEPSS 10 %dart · powertcp ftp for activex21 окт. 2008 г.
- CVE-2007-285639Наблюдать
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used
КритическаяCVSS 9,3Proof of conceptEPSS 7 %dart · powertcp zip compression24 мая 2007 г.
- CVE-2022-309539Наблюдать
Incorrect parsing of the backslash characters in Dart library
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dart · dart software development kit27 окт. 2022 г.
- CVE-2007-285538Наблюдать
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %dart · dart ziplite compression24 мая 2007 г.
- CVE-2021-2256835Наблюдать
Dart - Publishing to third-party package repositories may expose pub.dev credentials
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dart · dart software development kit9 дек. 2021 г.
- CVE-2012-538932Наблюдать
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (applicati
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %dart · powertcp webserver for activex23 янв. 2020 г.
- CVE-2022-045126Наблюдать
Auth bypass in Dark SDK
СредняяCVSS 6,5Эксплойта нетEPSS 1 %dart · dart software development kit18 февр. 2022 г.
- CVE-2026-2770426Наблюдать
Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction
СредняяCVSS 6,6Эксплойта нетEPSS 1 %dart · dart software development kit25 февр. 2026 г.
- CVE-2020-3566925Наблюдать
An issue was discovered in the http package through 0.12.2 for Dart.
СредняяCVSS 6,1Proof of conceptEPSS 2 %dart · http23 дек. 2020 г.
- CVE-2021-2254024Наблюдать
Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %dart · dart software development kit22 апр. 2021 г.
- CVE-2014-12509824Наблюдать
Dart http_server Directory Listing virtual_directory.dart VirtualDirectory cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %dart · http server10 апр. 2023 г.
- CVE-2020-892324Наблюдать
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM
СредняяCVSS 6,1Эксплойта нетEPSS 0 %dart · dart software development kit26 мар. 2020 г.
- CVE-2012-381921Наблюдать
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, all
СредняяCVSS 5,0Proof of conceptEPSS 2 %dart · powertcp activex4 окт. 2012 г.
- CVE-2021-2256714Наблюдать
Bidirectional Override in Dart SDK
НизкаяCVSS 3,5Эксплойта нетEPSS 1 %dart · dart software development kit5 янв. 2022 г.