0 Comentarios
0 Acciones
6K Vistas
0 Reseñas
Buscar
Descubre nuevas personas, crea nuevas conexiones y haz nuevos amigos
-
Inicia sesión para indicar que te gusta, compartir y comentar.
-
CVE-2026-12866: expr-eval Library Code Execution Vulnerability PatchedSummaryCVE-2026-12866 is a critical vulnerability in the expr-eval library, which allowed an attacker to execute arbitrary JavaScript by supplying crafted expressions. This could lead to unauthorized code execution within the application's context, posing a significant security risk.Understanding the Vulnerability: Code Execution in expr-evalThe expr-eval library w...CVE-2026-12866: expr-eval Library Code Execution Vulnerability PatchedSummaryCVE-2026-12866 is a critical vulnerability in the expr-eval library, which allowed an attacker to execute arbitrary JavaScript by supplying crafted expressions. This could lead to unauthorized code execution within the application's context, posing a significant security risk.Understanding the Vulnerability: Code Execution in expr-evalThe expr-eval library w...CVE-2026-12866: expr-eval Library Code Execution Vulnerability PatchedCVE-2026-12866: expr-eval Library Code Execution Vulnerability PatchedSummaryCVE-2026-12866 is a critical vulnerability in the expr-eval library, which allowed an attacker to execute arbitrary JavaScript by supplying crafted expressions. This could lead to unauthorized code execution, potentially resulting in data tampering, sensitive information disclosure, or even system compromise. The...0 Comentarios 0 Acciones 8K Vistas 0 Reseñas
-
CVE-2026-4983 - Detalji CVSS, EPSS unud Kev | CVE Find (Latvian)CVE-2026-4983 - Detalji CVSS, EPSS unud Kev | CVE FindSummary (Latvian)CVE-2026-4983 - detaljai CVSS, EPSS unud Kev | CVE FindWhat the vulnerability/exploit is about (Latvian)CVE-2026-4983 - šajā vijom ir problēma ar Open VSX Registry, kas neapstrādā SVG failus, kas tiek ielādēti kā ekspansiņas ikonas, un tās servisā izmanto Content-Type: image/svg+xml bez drošības nosaukumu, piemēram,...0 Comentarios 0 Acciones 1K Vistas 0 Reseñas
-
Open VSX Registry Vulnerability Allows Stored XSS and Session HijackingOpen VSX Registry Vulnerability Allows Stored XSS and Session HijackingSummaryOpen VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment, allowing an attacker to publish an extension with a malicious SVG icon and achieve...0 Comentarios 0 Acciones 3K Vistas 0 Reseñas
-
Tijelo (Tijela) (Croatian) (Croatian)Tijelo (Tijela) (Croatian)Summary (Summary) (Croatian)CVE-2026-4983 je oznaka za zločin u informacijskoj tehnologiji, koji se koristi za identifikaciju i opisivanje vjerovatnoćnih i eksponenata za sigurnost aplikacija. CVE-2026-4983 je zločin tipa "Cross-site Scripting" (XSS), što znači da se koristi za izrađivanje kriptografije na web stranici.What the vulnerability/exploit is about...0 Comentarios 0 Acciones 1K Vistas 0 Reseñas
-
Tiltavimas ir šaliošių securiteto užklausos (Lithuanian)Tiltavimas ir šaliošių securiteto užklausosSummaryŠis dokumentas aprašytas CVE-2026-4983, kuris yra Open VSX Registry (Open Source Visual Studio Extensions) platformos atvejį. Šis atvejis leidžia atakoti vartotojams naudojant malina SVG ikoną, skirtą visuotinio šaliošių securiteto užklausoms. Tai gali sukurti stored cross-site scripting (XSS) problemą, kai vartotojas atvaizduos ikoną URL.What...0 Comentarios 0 Acciones 1K Vistas 0 Reseñas
-
Titel (i dansk)Titel (i dansk)Sammendrag (i dansk)Hvad er vulnerability/exploitet omkring?Open VSX Registry ikke sanitiserer SVG-filer der bliver uploade som ekstensionsikoner f├©r lagring, og servere dem med Content-Type: image/svg+xml uden sikkerhedsheder som Content-Security-Policy eller Content-Disposition: attachment. Det g├©r det muligt for et attacker at publicere en ekstension med en misbrugelig...0 Comentarios 0 Acciones 3K Vistas 0 Reseñas
-
Titel (in Dutch)Titel (in Dutch)Samenvatting (in Dutch)Dezeelcode van de package `expr-eval` is ge├»nfectueerd met Code Execution via het toJSFunction() API. Een aanvaller kan door gemaakte expressies compileren in natieve code en dan direct uitgevoerde JavaScript uitvoeren, wat een sandbox verlaat en arbitraire code in de context van de applicatie kan uitvoeren.Wat het vulnere exploit is overDezeelcode van de...0 Comentarios 0 Acciones 875 Vistas 0 Reseñas
-
Titel (in Dutch)Titel (in Dutch)Samenvatting (in Dutch)Deze vulnereer is expr-eval, een JavaScript bibliotheek die gebruikt wordt om expressies te evalueren. Deze bibliotheek heeft een codeinjectievulnereer waarbij een aanvaller via de toJSFunction() API arbitraire JavaScript kan uitvoeren. Dit gebeurt omdat gebruikersge├»ntroduceerde expressies direct worden omgezet naar uitvoerbare JavaScript, waardoor...0 Comentarios 0 Acciones 3K Vistas 0 Reseñas
-
Titel (in Dutch) (Dutch)Titel (in Dutch)Samenvatting (in Dutch)Het artikel beschrijft een belangrijke security-issue die zich voordoet in de GPAC library, een open-source multimedia library. Het probleem is dat de versie 26.02.0 van GPAC kan worden geïnfecteerd door een onbekende component van het bestand src/utils/base_encoding.c van de ISOBMFF Parser module. Als deze component wordt manipuleerd, kan er...0 Comentarios 0 Acciones 2K Vistas 0 Reseñas
-
Titel (in Dutch) (Dutch)Titel (in Dutch)Samenvatting (in Dutch)Dezeur GPAC heeft een onbekende deel van het bestand src/utils/base_encoding.c van het component ISOBMFF Parser geïmplementeerd. Als deze manipulatie wordt uitgevoerd, kan er hoogcompressede data worden gegenereerd. De aanval moet lokaal worden uitgevoerd. Het exploit is beschikbaar voor de publiek en kan worden gebruikt voor aanvallen. Dit patcht het...0 Comentarios 0 Acciones 2K Vistas 0 Reseñas
-
Titel (in Dutch) (Dutch)Titel (in Dutch)Samenvatting (in Dutch)Dezeur GPAC tot versie 26.02.0 bevat een onbekende component van het bestand src/utils/base_encoding.c van de ISOBMFF Parser. Als deze component wordt manipuleerd, kan er hoogcompressiedata worden gegenereerd. De aanval moet lokale toegang hebben. Het exploit is openbaar beschikbaar en kan worden gebruikt voor aanvallen. Dit patchen wordt genoemd als...0 Comentarios 0 Acciones 2K Vistas 0 Reseñas
Resultados de la búsqueda