🎯 New Report #2686750: MozillaVPN: Elevation of Privilege via a Logic Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2024-08-28
⏰ Disclosed: 2025-07-03 13:34:52
📝 Summary: The MozillaVPN vulnerability was a logic flaw that allowed an unprivileged attacker to gain root privileges on macOS during the installation process. The issue was a bypass for a previously fixed vulnerability and involved the use of symbolic links.
@hackeronereports
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2024-08-28
⏰ Disclosed: 2025-07-03 13:34:52
📝 Summary: The MozillaVPN vulnerability was a logic flaw that allowed an unprivileged attacker to gain root privileges on macOS during the installation process. The issue was a bypass for a previously fixed vulnerability and involved the use of symbolic links.
@hackeronereports
🎯 New Report #2261577: MozillaVPN: Elevation of Privilege via a Race Condition Vulnerability
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2023-11-22
⏰ Disclosed: 2025-07-03 13:22:28
📝 Summary: A race condition vulnerability was discovered in Mozilla VPN that led to local privilege escalation to root on macOS. The vulnerability existed during the installation or update process, where a local attacker could replace the VPN binary with a malicious one that would execute as root. The issue was assigned a medium severity, as it required access to the local device. The vulnerability was addressed in version 2.20 of the software.
@hackeronereports
🔺Severity: Medium
👽 Reporter: northsea
💼 Team: Mozilla
💵 Bounty: null
🕐 Submitted: 2023-11-22
⏰ Disclosed: 2025-07-03 13:22:28
📝 Summary: A race condition vulnerability was discovered in Mozilla VPN that led to local privilege escalation to root on macOS. The vulnerability existed during the installation or update process, where a local attacker could replace the VPN binary with a malicious one that would execute as root. The issue was assigned a medium severity, as it required access to the local device. The vulnerability was addressed in version 2.20 of the software.
@hackeronereports
🎯 New Report #3235428: CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
⏰ Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: skrcprst
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-03
⏰ Disclosed: 2025-07-03 22:57:44
📝 Summary: null
@hackeronereports
🎯 New Report #2981303: TLS Cipher Misconfiguration in HTTP/3/QUIC Support
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
⏰ Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🔺Severity: null
👽 Reporter: zzq1015
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-02-07
⏰ Disclosed: 2025-07-06 21:05:11
📝 Summary: null
📂 Report JSON File: 2981303
@hackeronereports
🎯 New Report #1813453: [MK8DX Improper ranking/replay file parsing](https://hackerone.com/reports/1813453)
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
⏰ Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports
🔺Severity: Critical
👽 Reporter: crazy man123
🛠 State: resolved
💼 Team: Nintendo
💵 Bounty: null
🕐 Submitted: 2022-12-21
⏰ Disclosed: 2025-07-06 23:23:12
📝 Summary: The vulnerability in the Mario Kart 8 Deluxe game involved improper ranking and replay file parsing. This allowed for potential exploitation, leading to potentially unintended consequences.
📂 Report JSON File: 1813453
@hackeronereports
🎯 New Report #2859735: curl --continue-at confusion
🔺Severity: Medium
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-22
⏰ Disclosed: 2025-07-07 10:18:26
📝 Summary: null
📂 Report JSON File: 2859735
@hackeronereports
🔺Severity: Medium
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-22
⏰ Disclosed: 2025-07-07 10:18:26
📝 Summary: null
📂 Report JSON File: 2859735
@hackeronereports
🎯 New Report #2853023: Information Disclosure at : https://curl.se/.mailmap
🔺Severity: High
👽 Reporter: haithamzakaria
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-20
⏰ Disclosed: 2025-07-07 10:18:15
📝 Summary: null
📂 Report JSON File: 2853023
@hackeronereports
🔺Severity: High
👽 Reporter: haithamzakaria
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-20
⏰ Disclosed: 2025-07-07 10:18:15
📝 Summary: null
📂 Report JSON File: 2853023
@hackeronereports
🎯 New Report #2841436: information disclosure
🔺Severity: None
👽 Reporter: rono 07
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-14
⏰ Disclosed: 2025-07-07 10:18:05
📝 Summary: null
📂 Report JSON File: 2841436
@hackeronereports
🔺Severity: None
👽 Reporter: rono 07
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-14
⏰ Disclosed: 2025-07-07 10:18:05
📝 Summary: null
📂 Report JSON File: 2841436
@hackeronereports
🎯 New Report #2831558: netrc crlf injection
🔺Severity: null
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-09
⏰ Disclosed: 2025-07-07 10:17:55
📝 Summary: null
📂 Report JSON File: 2831558
@hackeronereports
🔺Severity: null
👽 Reporter: nyymi
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-09
⏰ Disclosed: 2025-07-07 10:17:55
📝 Summary: null
📂 Report JSON File: 2831558
@hackeronereports
🎯 New Report #2861797: curl mishandles ` ` sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🔺Severity: null
👽 Reporter: mdakh404
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-23
⏰ Disclosed: 2025-07-07 10:17:41
📝 Summary: null
📂 Report JSON File: 2861797
@hackeronereports
🎯 New Report #2864414: Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink()
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🔺Severity: High
👽 Reporter: aadityaathehacker
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:31
📝 Summary: null
📂 Report JSON File: 2864414
@hackeronereports
🎯 New Report #2864859: -H with space prefix leads to previous header injection when used with --proxy
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🔺Severity: Medium
👽 Reporter: spongebhav
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-11-25
⏰ Disclosed: 2025-07-07 10:17:20
📝 Summary: null
📂 Report JSON File: 2864859
@hackeronereports
🎯 New Report #2904921: OS Command Injection (subprocess Module Usage)
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
⏰ Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports
🔺Severity: Low
👽 Reporter: bulter
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-17
⏰ Disclosed: 2025-07-07 10:17:09
📝 Summary: null
📂 Report JSON File: 2904921
@hackeronereports
🎯 New Report #2915426: Git repository found
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
⏰ Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🔺Severity: High
👽 Reporter: tefa
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2024-12-27
⏰ Disclosed: 2025-07-07 10:16:58
📝 Summary: null
📂 Report JSON File: 2915426
@hackeronereports
🎯 New Report #3238249: Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
⏰ Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🔺Severity: Medium
👽 Reporter: extramayoextracheeseextrafries
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-06
⏰ Disclosed: 2025-07-07 10:16:48
📝 Summary: null
📂 Report JSON File: 3238249
@hackeronereports
🎯 New Report #2402842: Information disclosure identified on IBM endpoint.
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
⏰ Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🔺Severity: Medium
👽 Reporter: devire
🛠 State: resolved
💼 Team: IBM
💵 Bounty: null
🕐 Submitted: 2024-03-05
⏰ Disclosed: 2025-07-08 14:50:58
📝 Summary: The information disclosure vulnerability identified on an IBM endpoint was reported to IBM, analyzed, and remediated.
📂 Report JSON File: 2402842
@hackeronereports
🎯 New Report #3230359: CSRF at Network feature
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
⏰ Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🔺Severity: Medium
👽 Reporter: psfauzi
🛠 State: resolved
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-30
⏰ Disclosed: 2025-07-08 14:19:58
📝 Summary: A CSRF vulnerability was found in the network feature, where an attacker could change the Network Routing settings by sending a CSRF script to the victim.
📂 Report JSON File: 3230359
@hackeronereports
🎯 New Report #3241304: access notes without permission
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:54:37
📝 Summary: null
📂 Report JSON File: 3241304
@hackeronereports
🎯 New Report #3241308: Disclosure of email addresses
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports
🔺Severity: None
👽 Reporter: haydradz
🛠 State: not-applicable
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-07-08
⏰ Disclosed: 2025-07-08 19:53:51
📝 Summary: null
📂 Report JSON File: 3241308
@hackeronereports
🎯 New Report #1485717: ReDoS in IPAddr
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-19
⏰ Disclosed: 2025-07-08 22:57:09
📝 Summary: The Ruby IPAddr library was found to be vulnerable to a ReDoS (Regular Expression Denial of Service) vulnerability. The vulnerability was identified in the
📂 Report JSON File: 1485717
@hackeronereports
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-19
⏰ Disclosed: 2025-07-08 22:57:09
📝 Summary: The Ruby IPAddr library was found to be vulnerable to a ReDoS (Regular Expression Denial of Service) vulnerability. The vulnerability was identified in the
mask! method, which used a regular expression that was susceptible to exponential backtracking when processing malformed input. This could have led to a denial of service condition when the library was used to process user-supplied IP addresses.📂 Report JSON File: 1485717
@hackeronereports
🎯 New Report #1487889: ReDoS in Psych
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-21
⏰ Disclosed: 2025-07-08 22:56:51
📝 Summary: The Psych library in Ruby was found to have a ReDoS (Regular Expression Denial of Service) vulnerability in the parsing of time strings. The vulnerability was identified in the regular expression used to extract date and time information from the input string. The regular expression was susceptible to catastrophic backtracking, which could lead to significant performance degradation when parsing malformed input.
📂 Report JSON File: 1487889
@hackeronereports
🔺Severity: null
👽 Reporter: ooooooo q
🛠 State: resolved
💼 Team: Ruby
💵 Bounty: null
🕐 Submitted: 2022-02-21
⏰ Disclosed: 2025-07-08 22:56:51
📝 Summary: The Psych library in Ruby was found to have a ReDoS (Regular Expression Denial of Service) vulnerability in the parsing of time strings. The vulnerability was identified in the regular expression used to extract date and time information from the input string. The regular expression was susceptible to catastrophic backtracking, which could lead to significant performance degradation when parsing malformed input.
📂 Report JSON File: 1487889
@hackeronereports