Internet Bug Bounty - HackerOne Reports
View on HackerOne674
Total Reports
35
Critical
123
High
194
Medium
138
Low
CVE-2023-28710 Apache Airflow Spark Provider Arbitrary File Read via JDBC
Reported by:
sw0rd1ight
|
Disclosed:
Medium
Weakness: Improper Input Validation
Bounty: $2400.00
CVE-2019-11043: a buffer underflow in fpm_main.c can lead to RCE in php-fpm
Reported by:
neex
|
Disclosed:
Critical
Weakness: Buffer Underflow
Bounty: $1500.00
CVEs:
CVE-2019-11043
Use-after-free in PHP7's unserialize()
Reported by:
ryat
|
Disclosed:
Medium
Weakness: Use After Free
CVE-2019-0196: mod_http2 with scoreboard Use-After-Free (Read)
Reported by:
cy1337
|
Disclosed:
Medium
Weakness: Use After Free
CVE-2024-2398: HTTP/2 push headers memory-leak
Reported by:
w0x42
|
Disclosed:
Medium
Bounty: $2580.00
Type Confusion in Object Deserialization
Reported by:
ryat
|
Disclosed:
Medium
Weakness: Type Confusion
Use After Free in unserialize()
Reported by:
ryat
|
Disclosed:
Medium
Weakness: Use After Free
GMP Deserialization Type Confusion Vulnerability [MyBB <= 1.8.3 RCE Vulnerability]
Reported by:
ryat
|
Disclosed:
High
Weakness: Code Injection
Possible ReDoS vulnerability in query parameter filtering in Action Dispatch
Reported by:
scyoon
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
CVEs:
CVE-2024-41128
CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print()
Reported by:
geeknik
|
Disclosed:
High
Weakness: Memory Corruption - Generic
CVE-2017-5341 The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print()
Reported by:
geeknik
|
Disclosed:
High
Weakness: Memory Corruption - Generic
CVE-2017-5342 In tcpdump before 4.9.0 a bug in multiple protocol parsers could cause a buffer overflow in print-ether.c:ether_print()
Reported by:
geeknik
|
Disclosed:
High
Weakness: Memory Corruption - Generic
CVE-2017-5484 The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print()
Reported by:
geeknik
|
Disclosed:
High
Weakness: Memory Corruption - Generic
CVE-2023-28755: ReDoS vulnerability in URI
Reported by:
dee-see
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
CVEs:
CVE-2023-28755
wddx_deserialize use-after-free
Reported by:
fms
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $500.00
imap_rfc822_parse_headers GS Violation
Reported by:
fms
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $500.00
Additional information for CVE-2016-5699
Reported by:
ecbftw
|
Disclosed:
Linux kernel: CVE-2017-7308: a signedness issue in AF_PACKET sockets
Reported by:
xairy
|
Disclosed:
High
Weakness: Memory Corruption - Generic
CVEs:
CVE-2017-7308
Linux kernel: CVE-2017-1000112: a memory corruption due to UFO to non-UFO path switch
Reported by:
xairy
|
Disclosed:
High
Weakness: Memory Corruption - Generic
CVEs:
CVE-2017-1000112
Negative size parameter (-1) in memcpy mbfl_strcut
Reported by:
fms
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $1000.00