Pandora

Pandora

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 09.09.2026 21:37:52
  • Zuletzt bearbeitet 10.09.2026 15:43:03

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within ...

  • EPSS 0.32%
  • Veröffentlicht 17.08.2026 21:00:12
  • Zuletzt bearbeitet 26.08.2026 16:49:35

Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was inserted directly into the inline JavaScript onclick handler used by the Submit to Lo...

  • EPSS 0.28%
  • Veröffentlicht 17.08.2026 20:52:42
  • Zuletzt bearbeitet 26.08.2026 16:49:35

Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF using Pandora's content-based file-type detection, but previ...

  • EPSS 0.25%
  • Veröffentlicht 15.08.2026 21:56:44
  • Zuletzt bearbeitet 26.08.2026 16:49:35

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit ...

  • EPSS 0.41%
  • Veröffentlicht 15.08.2026 21:39:09
  • Zuletzt bearbeitet 26.08.2026 16:49:35

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extract...

  • EPSS 1.28%
  • Veröffentlicht 16.12.2017 02:29:10
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.