Dart kayıtları
dart üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %14,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-284 Improper Access Control1
- CWE-305 Authentication Bypass by Primary Weakness1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2008-4652Kavram kanıtı | Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execdart · powertcp ftp for activex · CWE-119 | Kritik9,3 | — | %10,1 | 21 Eki 2008 |
39İzleyin | CVE-2007-2856Kavram kanıtı | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is useddart · powertcp zip compression · CWE-119 | Kritik9,3 | — | %7,2 | 24 May 2007 |
39İzleyin | CVE-2022-3095İstismar yok | Incorrect parsing of the backslash characters in Dart librarydart · dart software development kit · CWE-20 | Kritik9,8 | — | %0,9 | 27 Eki 2022 |
38İzleyin | CVE-2007-2855İstismar yok | Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote dart · dart ziplite compression · CWE-119 | Kritik9,3 | — | %4,8 | 24 May 2007 |
35İzleyin | CVE-2021-22568İstismar yok | Dart - Publishing to third-party package repositories may expose pub.dev credentialsdart · dart software development kit · CWE-255 | Yüksek8,8 | — | %0,9 | 9 Ara 2021 |
32İzleyin | CVE-2012-5389İstismar yok | NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (applicatidart · powertcp webserver for activex · CWE-476 | Yüksek7,5 | — | %6,6 | 23 Oca 2020 |
26İzleyin | CVE-2022-0451İstismar yok | Auth bypass in Dark SDKdart · dart software development kit · CWE-305 | Orta6,5 | — | %1,0 | 18 Şub 2022 |
26İzleyin | CVE-2026-27704İstismar yok | Dart SDK and Flutter SDK have Zip slip in Dart Pub package extractiondart · dart software development kit · CWE-22 | Orta6,6 | — | %0,5 | 25 Şub 2026 |
25İzleyin | CVE-2020-35669Kavram kanıtı | An issue was discovered in the http package through 0.12.2 for Dart.dart · http · CWE-74 | Orta6,1 | — | %2,2 | 23 Ara 2020 |
24İzleyin | CVE-2021-22540İstismar yok | Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.dart · dart software development kit · CWE-79 | Orta6,1 | — | %0,7 | 22 Nis 2021 |
24İzleyin | CVE-2014-125098İstismar yok | Dart http_server Directory Listing virtual_directory.dart VirtualDirectory cross site scriptingdart · http server · CWE-79 | Orta6,1 | — | %0,6 | 10 Nis 2023 |
24İzleyin | CVE-2020-8923İstismar yok | An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM dart · dart software development kit · CWE-79 | Orta6,1 | — | %0,3 | 26 Mar 2020 |
21İzleyin | CVE-2012-3819Kavram kanıtı | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, alldart · powertcp activex · CWE-119 | Orta5,0 | — | %2,3 | 4 Eki 2012 |
14İzleyin | CVE-2021-22567İstismar yok | Bidirectional Override in Dart SDKdart · dart software development kit · CWE-284 | Düşük3,5 | — | %0,6 | 5 Oca 2022 |
- CVE-2008-465240Planlayın
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to exec
KritikCVSS 9,3Kavram kanıtıEPSS %10dart · powertcp ftp for activex21 Eki 2008
- CVE-2007-285639İzleyin
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used
KritikCVSS 9,3Kavram kanıtıEPSS %7dart · powertcp zip compression24 May 2007
- CVE-2022-309539İzleyin
Incorrect parsing of the backslash characters in Dart library
KritikCVSS 9,8İstismar yokEPSS %1dart · dart software development kit27 Eki 2022
- CVE-2007-285538İzleyin
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote
KritikCVSS 9,3İstismar yokEPSS %5dart · dart ziplite compression24 May 2007
- CVE-2021-2256835İzleyin
Dart - Publishing to third-party package repositories may expose pub.dev credentials
YüksekCVSS 8,8İstismar yokEPSS %1dart · dart software development kit9 Ara 2021
- CVE-2012-538932İzleyin
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (applicati
YüksekCVSS 7,5İstismar yokEPSS %7dart · powertcp webserver for activex23 Oca 2020
- CVE-2022-045126İzleyin
Auth bypass in Dark SDK
OrtaCVSS 6,5İstismar yokEPSS %1dart · dart software development kit18 Şub 2022
- CVE-2026-2770426İzleyin
Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction
OrtaCVSS 6,6İstismar yokEPSS %1dart · dart software development kit25 Şub 2026
- CVE-2020-3566925İzleyin
An issue was discovered in the http package through 0.12.2 for Dart.
OrtaCVSS 6,1Kavram kanıtıEPSS %2dart · http23 Ara 2020
- CVE-2021-2254024İzleyin
Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.
OrtaCVSS 6,1İstismar yokEPSS %1dart · dart software development kit22 Nis 2021
- CVE-2014-12509824İzleyin
Dart http_server Directory Listing virtual_directory.dart VirtualDirectory cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1dart · http server10 Nis 2023
- CVE-2020-892324İzleyin
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM
OrtaCVSS 6,1İstismar yokEPSS %0dart · dart software development kit26 Mar 2020
- CVE-2012-381921İzleyin
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, all
OrtaCVSS 5,0Kavram kanıtıEPSS %2dart · powertcp activex4 Eki 2012
- CVE-2021-2256714İzleyin
Bidirectional Override in Dart SDK
DüşükCVSS 3,5İstismar yokEPSS %1dart · dart software development kit5 Oca 2022