shopify-scripts - HackerOne Reports
View on HackerOne161
Total Reports
7
Critical
36
High
13
Medium
33
Low
Heap overflow due to off-by-one when expanding stack
Reported by:
titanous
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $800.00
SIGABRT in only mirb
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
Deleting Key-value pair from Frozen HASH or Clearing a Frozen HASH
Reported by:
an0n-j
|
Disclosed:
Weakness: Violation of Secure Design Principles
Use after free vulnerability in mruby Array#to_h causing DOS possible RCE
Reported by:
isra17
|
Disclosed:
Critical
Weakness: Code Injection
Heap use-after-free during range creation
Reported by:
titanous
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
Bounty: $200.00
Null pointer dereference regression in parse.y
Reported by:
haquaman
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Bounty: $1000.00
Null pointer dereference in mrb_str_concat
Reported by:
haquaman
|
Disclosed:
Weakness: Uncontrolled Resource Consumption
Invalid memory write caused by incorrect upper bound in array_copy
Reported by:
haquaman
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Bounty: $1000.00
SIGSEGV - mrb_check_intern_str() - NullPointer
Reported by:
ston3
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
Use After Free in str_replace
Reported by:
tunz
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $800.00
SIGSEGV - kh_resize_iv - Null Deref
Reported by:
ston3
|
Disclosed:
Low
Weakness: Uncontrolled Resource Consumption
SIGABRT - mirb - Double Free
Reported by:
ston3
|
Disclosed:
Weakness: Double Free
SIGABRT - mirb and mruby
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
SIGABRT - in free
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
SIGSEGV in mrb_vm_exec
Reported by:
ston3
|
Disclosed:
Weakness: NULL Pointer Dereference
SIGSEGV in str_buf_cat
Reported by:
ston3
|
Disclosed:
Weakness: Memory Corruption - Generic
SIGSEGV in mrb_class
Reported by:
ston3
|
Disclosed:
Weakness: NULL Pointer Dereference
Double free of filename after codegen error
Reported by:
titanous
|
Disclosed:
Weakness: Memory Corruption - Generic
Bounty: $200.00
SIGABRT - mrb_default_allocf
Reported by:
icanthack
|
Disclosed:
Low
Weakness: Memory Corruption - Generic
attempting double-free using the mruby compiler `mrbc`
Reported by:
geeknik
|
Disclosed:
High
Weakness: Memory Corruption - Generic