VYPR

Electron

by Pixelpost

npm: electron

Source repositories

CVEs (3)

  • CVE-2018-1000006HigJan 24, 2018
    risk 0.67cvss 8.8epss 0.84

    GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution…

  • CVE-2016-1202HigApr 25, 2016
    risk 0.44cvss 7.8epss 0.00

    Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.

  • CVE-2017-1000424MedJan 2, 2018
    risk 0.00cvss 4.3epss 0.01

    Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.