Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2021-22540

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering. The validation logic in dart:html for creating DOM nodes from text did not sanitize properly when it came across template tags.
Attacker Value
Unknown

CVE-2020-35669

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
Attacker Value
Unknown

CVE-2020-8923

Disclosure Date: March 26, 2020 (last updated February 21, 2025)
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you cannot update, we recommend you review the way you use the affected APIs, and pay special attention to cases where user-provided data is used to populate DOM nodes. Consider using Element.innerText or Node.text to populate DOM elements.
Attacker Value
Unknown

CVE-2012-5389

Disclosure Date: January 23, 2020 (last updated February 21, 2025)
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request.
Attacker Value
Unknown

CVE-2012-3819

Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request.
0
Attacker Value
Unknown

CVE-2008-4652

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.
0
Attacker Value
Unknown

CVE-2007-2855

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2856.
0
Attacker Value
Unknown

CVE-2007-2856

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.
0