Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2021-25916
Disclosure Date: March 16, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2020-28499
Disclosure Date: February 18, 2021 (last updated November 28, 2024)
All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
0
Attacker Value
Unknown
CVE-2020-28268
Disclosure Date: November 15, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
0
Attacker Value
Unknown
CVE-2020-8268
Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
0
Attacker Value
Unknown
CVE-2018-16469
Disclosure Date: October 30, 2018 (last updated November 27, 2024)
The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack.
0
Attacker Value
Unknown
CVE-2018-3753
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
0
Attacker Value
Unknown
CVE-2018-3752
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
0
Attacker Value
Unknown
CVE-2018-3722
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
0
Attacker Value
Unknown
CVE-2015-3360
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0