aboutcode-org / aboutcode-org/vulnerablecode
Invalid skipping of data based on summaries
- Linguagem predominante
- Python
- Estrelas
- 702
- Forks
- 328
- Merge médio
- 3d 8h
- PRs com merge (30d)
- 3
Descrição
Running importers and improvers:
```
Inconsistent summary for . Existing: Improper Handling of URL Encoding (Hex Encoding)
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded., provided: serve node module suffers fro
m Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Inconsistent summary for . Existing: CVE-2013-5612 Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106), provided: Cross-site scr
ipting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging
a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
Inconsistent summary for . Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for . Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for . Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for . Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for . Existing: Missing Authentication for Critical Function
```
Guia de contribuição
Nenhum guia de contribuição indexado para este repositório
Avaliação
Esta issue ainda não foi avaliada.