Filtered by vendor Agoric
Subscribe
Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-39532 | 1 Agoric | 1 Ses | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the confinement of guest applications under SES that may manifest as either the ability to exfiltrate information or execute arbitrary code depending on the configuration and implementation of the surrounding host.
Guest pr ...
Show More |
|||||
| CVE-2021-23594 | 1 Agoric | 1 Realms-shim | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
|
|||||
| CVE-2021-23543 | 1 Agoric | 1 Realms-shim | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
|
|||||