Lucene search

K

Pandora Security Vulnerabilities

cve
cve

CVE-2017-3194

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

8.1CVSS

7.6AI Score

0.005EPSS

2017-12-16 02:29 AM
28
cve
cve

CVE-2018-13144

The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.

7.5CVSS

7.6AI Score

0.001EPSS

2018-07-04 03:29 PM
24
cve
cve

CVE-2023-22898

workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).

6.5CVSS

6.3AI Score

0.001EPSS

2023-01-10 02:15 AM
18