shopify-scripts - HackerOne Reports
View on HackerOne161
Total Reports
7
Critical
36
High
13
Medium
33
Low
SIGSEGV on mruby's mark_tbl() (Invalid memory access)
Reported by:
jpenalbae
|
Disclosed:
High
Weakness: Memory Corruption - Generic
SIGSEGV in mrb_vm_exec
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
SIGSEGV - mrb_vm_exec - vm.c in line:1272
Reported by:
ston3
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Invalid handling of zero-length heredoc identifiers leads to infinite loop in the sandbox
Reported by:
dkasak
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Bounty: $10000.00
OP_SCALL in LHS of a OP_ASGN resulting in arbitrary memory write
Reported by:
avisaven
|
Disclosed:
Critical
Weakness: Write-what-where Condition
Interger overflow in str_substr leading to read/write out of bound memory
Reported by:
beyondchain
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Bounty: $100.00
Use After Free in mrb_vm_exec
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00
SIGABRT - method_missing - mark_context_stack
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
Heap Buffer overflow in mrb_ary_unshift
Reported by:
locator
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Bounty: $800.00
SIGSEV on mrb_ary_splice
Reported by:
jpenalbae
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Broken handling of maximum number of method call arguments leads to segfault
Reported by:
dkasak
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Bounty: $10000.00
Segmentation fault due to bad memory access in kh_get_mt
Reported by:
haquaman
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Bounty: $8000.00
SIGABRT, SIGSEGV mspace_free() and mrb_default_allocf()
Reported by:
ston3
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
heap-buffer-overflow on mruby
Reported by:
ahihi
|
Disclosed:
Weakness: Memory Corruption - Generic
mruby-time: Crash host with uninitialized Time obj
Reported by:
brakhane
|
Disclosed:
High
Weakness: Memory Corruption - Generic
Bounty: $8000.00
Crash: calling Proc::initialize_copy with a Proc instance where initialize never ran leads to a crash
Reported by:
brakhane
|
Disclosed:
High
Weakness: Memory Corruption - Generic
Bounty: $8000.00
Heap buffer oveflow with many arguments
Reported by:
titanous
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $800.00
Segmentation fault - mrb_gc_mark
Reported by:
alanbugz
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Crash: Initialize Decimal with itself triggers an assertion
Reported by:
brakhane
|
Disclosed:
High
Bounty: $10000.00
Aborted - proc.c - line:143
Reported by:
ston3
|
Disclosed:
Weakness: Uncontrolled Resource Consumption