Bug Bounty

HackerOne Bug Bounty Disclosure: account-takeover-of-existing-hackerone-accounts-through-scim-provisioning-boy-child

Company Name: HackerOne Company HackerOne URL: https://hackerone.com/security Submitted By:boy_child_Link to Submitters Profile:https://hackerone.com/boy_child_ Report Title:Account takeover of existing HackerOne accounts through...

HackerOne Bug Bounty Disclosure: use-after-free-in-openssl-keylog-callback-via-ssl-get-ex-data-in-libcurl-brobagazzzx

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:brobagazzzxLink to Submitters Profile:https://hackerone.com/brobagazzzx Report Title:Use-After-Free in OpenSSL Keylog Callback via SSL_get_ex_data()...

HackerOne Bug Bounty Disclosure: elevation-of-privileges-eop-vulnerabilities-related-to-the-some-easy-options-on-windows-justlikebono-official

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:justlikebono_officialLink to Submitters Profile:https://hackerone.com/justlikebono_official Report Title:Elevation of Privileges (EoP) vulnerabilities related to...

HackerOne Bug Bounty Disclosure: curl-doesn-t-hide-credentials-in-proc-xxx-cmdline-provided-via-cli-arguments-stogusho

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:stogushoLink to Submitters Profile:https://hackerone.com/stogusho Report Title:curl doesn't hide credentials in /proc/XXX/cmdline provided...

HackerOne Bug Bounty Disclosure: curl-easy-header-runs-at-o-n-or-worse-and-can-be-abused-to-use-minute-s-of-cpu-time-wolfsage

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:wolfsageLink to Submitters Profile:https://hackerone.com/wolfsage Report Title:curl_easy_header runs at O(N) or worse and...

HackerOne Bug Bounty Disclosure: curl-oj-allows-creating-custom-curlrc-file-which-allows-exfiltrating-private-data-among-other-things-wolfsage

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:wolfsageLink to Submitters Profile:https://hackerone.com/wolfsage Report Title:curl -OJ allows creating custom curlrc file...

HackerOne Bug Bounty Disclosure: heap-buffer-overflow-vulnerability-in-conncache-c-incorrect-use-of-pointer-arrays-resulting-in-out-of-bounds-memory-writes-freak-coding

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:freak_codingLink to Submitters Profile:https://hackerone.com/freak_coding Report Title:Heap buffer overflow vulnerability in conncachec: incorrect...