Anders Kaseorg
15 exploits
Active since Jun 2012
mosh < 1.2.1 - Authenticated Denial of Service via Escape Sequence with Large Repeat Count
Zulip Server 2.0.0-rc1-<10.4 - Cross-Site Scripting in Digest Preview
CVSS 6.8
Zulip Server 2.0.0-rc1-<10.4 - Cross-Site Scripting in Digest Preview
CVSS 6.8
zulip_server < 2.0.5 - Authenticated Denial of Service via Markdown Parser Regex
CVSS 6.5
Zulip Server 1.8.0-2.0.5 - Authenticated Stored Cross-Site Scripting via File Upload
CVSS 5.4
Zulip Server 1.9.0-2.0.8 - Open Redirect via Image Thumbnailing Handler
CVSS 6.1
zulip/zulip <3eb2791c3e9695f7d37ffe84e0c2184fae665cb6 - XSS
CVSS 5.4
Zulip Server >=2021-06-03 <2022-03-01 - Cross-Site Scripting via Malicious Full Name in Recent Topics Tooltip
CVSS 4.6
Zulip Server <5.5 - Privilege Escalation
CVSS 5.4
Zulip Server 5.0-5.6 - SCIM Bearer Token Timing Side-Channel Exposure
CVSS 3.7
Zulip Server - Stored Cross-Site Scripting in Message Feed Tooltips
CVSS 8.2
Zulip 8.3 - Cross-Site Scripting via construct_copy_div Function
CVSS 5.4
Zulip 8.3 - Cross-Site Scripting via replace_emoji_with_text Function
CVSS 5.4
Zulip Server 2.0.0-rc1-<10.4 - Cross-Site Scripting in Digest Preview
CVSS 6.8
Zulip Server 5.0-11.5 - Stored Cross-Site Scripting in Group and Channel Names
CVSS 5.4