shopify-scripts - HackerOne Reports
View on HackerOne161
Total Reports
7
Critical
36
High
13
Medium
33
Low
mrb_vformat() heap overflow could lead to code execution
Reported by:
mg36
|
Disclosed:
Weakness: Memory Corruption - Generic
kh_get_n2s() stack overrun
Reported by:
mg36
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Exception cause SIGABRT
Reported by:
isra17
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Interger overflow in str_substr leading to read/write out of bound memory
Reported by:
beyondchain
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Bounty: $100.00
Segmentation fault while printing backtrace
Reported by:
dgaletic
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Bounty: $1000.00
Null pointer dereference in OP_ENTER
Reported by:
dgaletic
|
Disclosed:
Low
Weakness: NULL Pointer Dereference
Bounty: $800.00
Null pointer dereferences in mrb_get_args
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00
heap use-after-free in mrb_vm_exec()
Reported by:
mg36
|
Disclosed:
SIGSEGV - mrb_obj_extend - line:413
Reported by:
ston3
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Use after free in mruby-mpdecimal
Reported by:
haquaman
|
Disclosed:
Weakness: Use After Free
Bounty: $800.00
sprintf gem - format string combined attack
Reported by:
aerodudrizzt
|
Disclosed:
Crash in ary_concat()
Reported by:
mg36
|
Disclosed:
Heap Buffer Overflow in mrb_hash_keys
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00
Crash: A call to Symbol.new leads to a crash when inspecting the resulting object
Reported by:
brakhane
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Bounty: $1000.00
SIGSEGV in mrb_vm_exec
Reported by:
ston3
|
Disclosed:
Weakness: NULL Pointer Dereference
heap-use-after-free in OP_RESCUE
Reported by:
ahihi
|
Disclosed:
Weakness: Use After Free
SIGSEGV in mrb_str_inum
Reported by:
ston3
|
Disclosed:
Weakness: NULL Pointer Dereference
heap use after free in fiber_switch
Reported by:
locator
|
Disclosed:
Bounty: $100.00
SIGABRT in mrb_debug_info_append_file
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
Invalid Pointer Reference from OP_RESCUE
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00