Show filters
273 Total Results
Displaying 211-220 of 273
Sort by:
Attacker Value
Unknown

CVE-2020-28458

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
Attacker Value
Unknown

CVE-2020-7792

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.
0
Attacker Value
Unknown

CVE-2020-7788

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
Attacker Value
Unknown

CVE-2020-7774

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
Attacker Value
Unknown

CVE-2020-28268

Disclosure Date: November 15, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-28271

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-28269

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-28270

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-7770

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
Attacker Value
Unknown

CVE-2020-7768

Disclosure Date: November 11, 2020 (last updated February 22, 2025)
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.