Show filters
131 Total Results
Displaying 21-30 of 131
Sort by:
Attacker Value
Unknown
CVE-2022-36938
Disclosure Date: November 11, 2022 (last updated November 08, 2023)
DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during processing of a 3rd party Android APK file.
0
Attacker Value
Unknown
CVE-2022-40138
Disclosure Date: October 11, 2022 (last updated October 08, 2023)
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.
0
Attacker Value
Unknown
CVE-2022-35289
Disclosure Date: October 11, 2022 (last updated October 08, 2023)
A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
0
Attacker Value
Unknown
CVE-2022-32234
Disclosure Date: October 11, 2022 (last updated October 08, 2023)
An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
0
Attacker Value
Unknown
CVE-2022-27810
Disclosure Date: October 06, 2022 (last updated October 08, 2023)
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.
0
Attacker Value
Unknown
CVE-2022-0209
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2020-20094
Disclosure Date: March 23, 2022 (last updated October 07, 2023)
Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages
0
Attacker Value
Unknown
CVE-2020-20093
Disclosure Date: March 23, 2022 (last updated October 07, 2023)
The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
0
Attacker Value
Unknown
CVE-2021-24044
Disclosure Date: January 15, 2022 (last updated October 07, 2023)
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.
0
Attacker Value
Unknown
CVE-2021-24045
Disclosure Date: December 13, 2021 (last updated October 07, 2023)
A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
0