Логотип exploitDog
bind:CVE-2025-46653
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-46653

Количество 5

Количество 5

ubuntu логотип

CVE-2025-46653

около 2 месяцев назад

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2025-46653

около 2 месяцев назад

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-46653

около 2 месяцев назад

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-46653

около 2 месяцев назад

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies ...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-75v8-2h7p-7m2m

около 2 месяцев назад

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-46653

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2025-46653

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-46653

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-46653

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies ...

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-75v8-2h7p-7m2m

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу