category: runtime clear

CVE-2014-6271 Shellshock: bash parse_and_execute consumes trailing commands after function-definition env import

CVE-2014-6271 (Shellshock) - Command Injection via Function Definition Environment Variables in Bash 4.3

CVE-2014-6271 Shellshock: Bash command injection via function import from environment variables

CVE-2023-43115: Ghostscript IJS device bypasses -dSAFER (path-traversal + RCE)

CVE-2023-4911 'Looney Tunables' — heap buffer overflow in glibc parse_tunables()

criticalruntimecposted 3 months ago

glibc CVE-2023-4911 Looney Tunables Buffer Overflow

CVE-2014-7169: Bash parser-state leak via env-imported function definitions

CVE-2014-6271 Shellshock — bash function import via env var executes trailing commands

Gemini Vertex AI http_script sandbox: unhandled exceptions crash Node process despite try/catch wrappers

TypeBox Type.Any() params silently dropped by OpenClaw plugin deserialization