Internet Bug Bounty - HackerOne Reports
View on HackerOne674
Total Reports
35
Critical
123
High
194
Medium
138
Low
Buffer Overflow in optimized_escape_html method
Reported by:
chamal
|
Disclosed:
Medium
Weakness: Classic Buffer Overflow
Mercurial git subrepo lead to arbritary command injection
Reported by:
pnig0s
|
Disclosed:
Critical
Weakness: Command Injection - Generic
Permissions policies can be bypassed via Module._load and require.extensions (High) (CVE-2023-30587)
Reported by:
mattaustin
|
Disclosed:
High
Weakness: Improper Access Control - Generic
Bounty: $1165.00
Leak of sensitive values to Airflow rendered template
Reported by:
jrs53
|
Disclosed:
Low
Weakness: Insecure Storage of Sensitive Information
Bounty: $480.00
CVE-2023-27538: SSH connection too eager reuse still
Reported by:
nyymi
|
Disclosed:
Low
Weakness: Business Logic Errors
Bounty: $480.00
CVE-2023-27533: TELNET option IAC injection
Reported by:
nyymi
|
Disclosed:
Low
Weakness: Business Logic Errors
Bounty: $480.00
CVE-2023-27534: SFTP path ~ resolving discrepancy
Reported by:
nyymi
|
Disclosed:
Low
Weakness: Business Logic Errors
Bounty: $480.00
Heap overflow due to integer overflow in bzdecompress() function
Reported by:
fosec
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
CVE-2023-27535: FTP too eager connection reuse
Reported by:
nyymi
|
Disclosed:
Medium
Weakness: Business Logic Errors
Bounty: $2400.00
imagefilltoborder stackoverflow on truecolor images
Reported by:
fms
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
Bounty: $500.00
Invalid parameter in memcpy function trough openssl_pbkdf2
Reported by:
emyei
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Bounty: $500.00
Misusing of FPU Instruction Could Cause Security Vulnerabilities in Adobe Flash Player
Reported by:
yopwn
|
Disclosed:
Weakness: Memory Corruption - Generic
CVEs:
CVE-2015-3100
Heap overflow due to integer overflow in php_escape_html_entities_ex() function
Reported by:
fosec
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Linux kernel: CVE-2017-6074: DCCP double-free vulnerability
Reported by:
xairy
|
Disclosed:
High
Weakness: Double Free
CVEs:
CVE-2017-6074
Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow
Reported by:
gogil
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $500.00
locale_accept_from_http out-of-bounds access
Reported by:
fms
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $500.00
Use After Free in unserialize() with Unexpected Session Deserialization
Reported by:
ryat
|
Disclosed:
Weakness: Memory Corruption - Generic
ntpd: read_mru_list() does inadequate incoming packet checks
Reported by:
magnusstubman
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
imagegif/output out-of-bounds access
Reported by:
fms
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $500.00
CVE-2016-4796 OpenJPEG color_cmyk_to_rgb Out-of-Bounds Read Vulnerability
Reported by:
binvul
|
Disclosed:
Weakness: Memory Corruption - Generic
CVEs:
CVE-2016-4796