Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Holblin

#19834of 53,630
13.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-7748
7.8
2023-11-16
Adobe · @Adobe/Css-Tools · CVE-2023-48631
**Name of the Vulnerable Software and Affected Versions** @adobe/css-tools versions 4.3.1 and earlier **Description** The issue is related to an Improper Input Validation vulnerability in the CSS parser for Node.js. This vulnerability could result in a denial of service while attempting to parse CSS, allowing a remote attacker to cause a service disruption. **Recommendations** For versions 4.3.1 and earlier, update to version 4.3.2 to resolve the issue.
PT-2023-7240
5.3
2023-08-16
Adobe · @Adobe/Css-Tools · CVE-2023-26364
**Name of the Vulnerable Software and Affected Versions** @adobe/css-tools versions 4.3.0 and earlier **Description** The issue is related to an Improper Input Validation vulnerability in the CSS parser for Node.js css-tools. This vulnerability could result in a denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges. **Recommendations** For versions 4.3.0 and earlier, update to version 4.3.1 to resolve the issue. As a temporary workaround, consider restricting the input to the CSS parser to minimize the risk of exploitation.