REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'SEMrush'
disclosed a bug submitted by
b'a_d_a_m'
b'CORS misconfiguration which leads to the disclosure of certain data concerning the user.'
15 Feb 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'rhyselsmore'
b'Filesystem Writes via `yarn install` via symlinks and tar transforms inside a crafted malicious package'
15 Feb 2020
b'Mail.ru'
disclosed a bug submitted by
b'rainbow_json'
b"[API] ICQ user's avatar can be manipulated remotely"
14 Feb 2020
b'Mail.ru'
disclosed a bug submitted by
b'rainbow_json'
b'[Web ICQ Client] XSS ?????????? ? ????? ????????????'
14 Feb 2020
b'Mail.ru'
disclosed a bug submitted by
b'rainbow_json'
b'[Web ICQ Client] XSS-inj in polls'
14 Feb 2020
b'Mail.ru'
disclosed a bug submitted by
b'rainbow_json'
b'IP address can be leaked on Image preview in ICQ for Android chat'
14 Feb 2020
b'Maximum'
disclosed a bug submitted by
b'rhetoric'
b"'X-Forwarded-Host' key used in input without sanitation - possible cache poisoning"
14 Feb 2020
b'Slack'
disclosed a bug submitted by
b'akaki'
b'URL filter bypass in Enterprise Grid'
14 Feb 2020
b'Node.js'
disclosed a bug submitted by
b'mpracucci'
b'Fix for CVE-2018-12122 can be bypassed via keep-alive requests'
13 Feb 2020
b'Node.js'
disclosed a bug submitted by
b'jzebor'
b'Pull Request #12949 - Security Implications without CVE assignment'
13 Feb 2020
b'Node.js'
disclosed a bug submitted by
b'jzebor'
b'Out of order TLS handshake / application data messages lead to segmentation fault'
13 Feb 2020
b'Node.js'
disclosed a bug submitted by
b'jasnell'
b'Denial of Service: nghttp2 use of uninitialized pointer'
13 Feb 2020
b'Node.js'
disclosed a bug submitted by
b'jzebor'
b'HTTP/2 Denial of Service Vulnerability'
13 Feb 2020
b'Node.js'
disclosed a bug submitted by
b'htuch'
b'Vulnerability in http-parser & embedded NULL header handling'
13 Feb 2020
b'NordVPN'
disclosed a bug submitted by
b'd4nt'
b'Clickjacking at join.nordvpn.com'
13 Feb 2020
b'Polymail, Inc.'
disclosed a bug submitted by
b'xaleraf4ra'
b'[share.polymail.io] XSS when uploading a file to the server'
13 Feb 2020
b'Data Processing (IBB)'
disclosed a bug submitted by
b'bugbasher'
b'Tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option() (CVE-2018-16229)'
13 Feb 2020
b'Data Processing (IBB)'
disclosed a bug submitted by
b'bugbasher'
b'Tcpdump before 4.9.3 has a buffer over-read in print-802_11.c (CVE-2018-16227)'
13 Feb 2020
b'Data Processing (IBB)'
disclosed a bug submitted by
b'geeknik'
b'tcpdump: CVE-2018-14879 - buffer overflow in tcpdump.c:get_next_file()'
13 Feb 2020
b'MobiSystems Ltd.'
disclosed a bug submitted by
b'emmano'
b'Firebase Firestore insecure database'
13 Feb 2020
1
...
321
322
323
324
325
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM