Show filters
326 Total Results
Displaying 261-270 of 326
Sort by:
Attacker Value
Unknown

CVE-2020-7771

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.
Attacker Value
Unknown

CVE-2020-28460

Disclosure Date: December 22, 2020 (last updated February 22, 2025)
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
Attacker Value
Unknown

CVE-2020-28448

Disclosure Date: December 22, 2020 (last updated February 22, 2025)
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
Attacker Value
Unknown

CVE-2020-28458

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
Attacker Value
Unknown

CVE-2020-7792

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.
0
Attacker Value
Unknown

CVE-2020-7788

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
Attacker Value
Unknown

CVE-2020-7774

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
Attacker Value
Unknown

CVE-2020-28268

Disclosure Date: November 15, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-28271

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-28269

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.