CWE-471
36 CVEs • Abstraction: Base
Modification of Assumed-Immutable Data (MAID)
The product does not properly protect an assumed-immutable element from being modified by an attacker.
CVEs (36)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 14, 2021 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid us...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 14, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker...Show more |
In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the type of the tensor is not an integral typ...Show more |
1Systeminformation 1Systeminformation Jun 17, 2026 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The i...Show more |
3Debian HighlightjsOracle3Debian Linux Highlight.jsMysql Enterprise MonitorJun 17, 2026 Nov 24, 2020 N/A· v4 8.7 HIGH· v3 4.9 MEDIUM· v2 Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype p...Show more |
1Json8 Merge Patch Project 1Json8 Merge Patch Jun 17, 2026 Nov 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor. |
1Object Path Project 1Object Path Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be...Show more |
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks. |
1Utils Extend Project 1Utils Extend Jun 17, 2026 Apr 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend. |
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects. |
1Defaults Deep Project 1Defaults Deep Nov 21, 2024 Jun 7, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or...Show more |
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or mod...Show more |
2Lodash Netapp3Active Iq Unified Manager LodashSystem ManagerNov 21, 2024 Jun 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Obje...Show more |
1Assign Deep Project 1Assign Deep Nov 21, 2024 Jun 7, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or mo...Show more |
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or mod...Show more |
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the pro...Show more |