agoric kayıtları
agoric üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2021-23594İstismar yok | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.agoric · realms-shim · CWE-1321 | Kritik10,0 | — | %1,8 | 10 Oca 2022 |
40Planlayın | CVE-2021-23543İstismar yok | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.agoric · realms-shim · CWE-1321 | Kritik9,8 | — | %1,8 | 10 Oca 2022 |
39İzleyin | CVE-2023-39532İstismar yok | SES's dynamic import and spread operator provides possible path to arbitrary exfiltration and executionagoric · ses · CWE-20 | Kritik9,8 | — | %1,3 | 8 Ağu 2023 |
- CVE-2021-2359441Planlayın
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
KritikCVSS 10,0İstismar yokEPSS %2agoric · realms-shim10 Oca 2022
- CVE-2021-2354340Planlayın
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
KritikCVSS 9,8İstismar yokEPSS %2agoric · realms-shim10 Oca 2022
- CVE-2023-3953239İzleyin
SES's dynamic import and spread operator provides possible path to arbitrary exfiltration and execution
KritikCVSS 9,8İstismar yokEPSS %1agoric · ses8 Ağu 2023