vulnerablecode icon indicating copy to clipboard operation
vulnerablecode copied to clipboard

Invalid skipping of data based on summaries

Open pombredanne opened this issue 3 years ago • 1 comments

Running importers and improvers:

Inconsistent summary for <Vulnerability: VULCOID-B5K>. Existing: Improper Handling of URL Encoding (Hex Encoding)
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded., provided: serve node module suffers fro
m Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Inconsistent summary for <Vulnerability: VULCOID-1BL1>. Existing: CVE-2013-5612 Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106), provided: Cross-site scr
ipting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging
 a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
Inconsistent summary for <Vulnerability: VULCOID-7A>. Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for <Vulnerability: VULCOID-7A>. Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for <Vulnerability: VULCOID-7A>. Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for <Vulnerability: VULCOID-7A>. Existing: , provided: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
erform out of bounds memory access via a crafted HTML page.
Inconsistent summary for <Vulnerability: VULCOID-A7X>. Existing: Missing Authentication for Critical Function

pombredanne avatar Sep 09 '22 15:09 pombredanne

relates to https://github.com/nexB/vulnerablecode/issues/859

TG1999 avatar Sep 09 '22 15:09 TG1999