doowb

4 exploits Active since Jun 2018
CVE-2018-3719 WRITEUP HIGH WRITEUP
mixin-deep <1.3.1 - Use After Free
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVSS 8.8
CVE-2018-3720 WRITEUP HIGH WRITEUP
assign-deep <0.4.7 - Use After Free
assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVSS 8.8
CVE-2018-3722 WRITEUP HIGH WRITEUP
merge-deep <3.0.1 - Use After Free
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVSS 8.8
CVE-2018-3723 WRITEUP HIGH WRITEUP
defaults-deep <0.2.4 - Use After Free
defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVSS 8.8