Mario Heiderich
8 exploits
Active since Sep 2010
DOMPurify 2.5.3-2.5.8/3.1.3-3.3.1 - XSS
CVSS 6.1
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
CVSS 6.1
Typora < 0.9.81 - Remote Code Execution via Mermaid Code Block XSS
CVSS 9.6
DOMPurify < 2.5.4 - Cross-Site Scripting Bypass via Depth Check Evasion
CVSS 7.3
DOMPurify < 3.2.4 - Cross-Site Scripting via Incorrect Template Literal Regular Expression
CVSS 4.5
Microsoft Internet Explorer 8 - Auth Bypass
Cryptocat < 2.0.22 - Information Disclosure via img/keygen.gif
CVSS 7.5
Cryptocat < 2.0.22 - Remote Script Injection via Improper Input Sanitization
CVSS 9.8