Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-38834

Disclosure Date: April 05, 2022 (last updated October 07, 2023)
easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.
Attacker Value
Unknown

CVE-2020-7616

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.
Attacker Value
Unknown

python-dbusmock arbitrary code execution or file overwrite when templates are l…

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.
0
Attacker Value
Unknown

CVE-2017-16106

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2016-6299

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.
0