CVE-2020-25489
Published Sep 17, 2020A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.
Vendor archive
2 CVEs tagged to vendor sqreen — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual mac…