Show filters
346 Total Results
Displaying 341-346 of 346
Sort by:
Attacker Value
Unknown
CVE-2020-7600
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.
0
Attacker Value
Unknown
CVE-2020-7598
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
0
Attacker Value
Unknown
CVE-2019-10808
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
0
Attacker Value
Unknown
CVE-2020-5258
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
0
Attacker Value
Unknown
CVE-2019-10806
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
0
Attacker Value
Unknown
CVE-2020-8116
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
0