shopify-scripts - HackerOne Reports
View on HackerOne161
Total Reports
7
Critical
36
High
13
Medium
33
Low
SIGSEGV - mrb_vm_exec - line:1312
Reported by:
ston3
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Null pointer dereference in 'get_file'
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00
Null pointer derefence due to bug in codegen with negation without using value
Reported by:
haquaman
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Bounty: $10000.00
Null pointer dereference due to bug in codegen with negation of floats
Reported by:
haquaman
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Segfault when passing invalid values to `values_at`
Reported by:
dkasak
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Bounty: $1000.00
SEGV on ary_concat
Reported by:
ahihi
|
Disclosed:
Weakness: Memory Corruption - Generic
SIGSEGV - mark_context_stack
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
mirb only: stack-buffer-overflow (OOB write) in main()
Reported by:
geeknik
|
Disclosed:
High
Weakness: Stack Overflow
Invalid Pointer reference in L_RESCUE
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $100.00
Null pointer dereference due to TOCTTOU bug in mrb_time_initialize
Reported by:
raydot
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Recursion causing uninitialized memory reads leading to a segfault
Reported by:
dgaletic
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Bounty: $2000.00
Segmentfault at mrb_vm_exec
Reported by:
locator
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
Bounty: $100.00
SIGSEGV - vm.c - line:1214
Reported by:
ston3
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
SIGSEGV on mrb_vm_exec() Null Deref
Reported by:
ston3
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Heap Overflow in mrb_arb_splice
Reported by:
tunz
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Bounty: $800.00
Integer Overflow in mrb_ary_set
Reported by:
tunz
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $100.00
SIGSEGV Null Pointer mrb_str_concat()
Reported by:
ston3
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
mrb_vformat() heap overflow could lead to code execution
Reported by:
mg36
|
Disclosed:
Weakness: Memory Corruption - Generic
Memory disclosure in timegm
Reported by:
volc
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Bounty: $1000.00
Invalid Pointer Reference from OP_RESCUE
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00