Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2021-25916

Disclosure Date: March 16, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-28499

Disclosure Date: February 18, 2021 (last updated November 28, 2024)
All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
Attacker Value
Unknown

CVE-2020-28268

Disclosure Date: November 15, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-8268

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Attacker Value
Unknown

CVE-2018-16469

Disclosure Date: October 30, 2018 (last updated November 27, 2024)
The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack.
Attacker Value
Unknown

CVE-2018-3753

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
0
Attacker Value
Unknown

CVE-2018-3752

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
0
Attacker Value
Unknown

CVE-2018-3722

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
0
Attacker Value
Unknown

CVE-2015-3360

Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0