CVE-2026-88069
- EPSS 0.33%
- Veröffentlicht 09.09.2026 21:37:52
- Zuletzt bearbeitet 10.09.2026 15:43:03
Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within ...
- EPSS 0.32%
- Veröffentlicht 17.08.2026 21:00:12
- Zuletzt bearbeitet 26.08.2026 16:49:35
Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was inserted directly into the inline JavaScript onclick handler used by the Submit to Lo...
CVE-2026-75529
- EPSS 0.28%
- Veröffentlicht 17.08.2026 20:52:42
- Zuletzt bearbeitet 26.08.2026 16:49:35
Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF using Pandora's content-based file-type detection, but previ...
CVE-2026-74767
- EPSS 0.25%
- Veröffentlicht 15.08.2026 21:56:44
- Zuletzt bearbeitet 26.08.2026 16:49:35
Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit ...
- EPSS 0.41%
- Veröffentlicht 15.08.2026 21:39:09
- Zuletzt bearbeitet 26.08.2026 16:49:35
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extract...
CVE-2017-3194
- EPSS 1.28%
- Veröffentlicht 16.12.2017 02:29:10
- Zuletzt bearbeitet 13.05.2026 00:24:29
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.