VYPR
Vendor

Macdown Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2019-12173HigMay 18, 2019
    risk 0.58cvss 8.8epss 0.04

    MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element. This is different from CVE-2019-12138.

  • CVE-2019-12138HigMay 16, 2019
    risk 0.51cvss 7.8epss 0.01

    MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.