42.4.1
14 years ago
6 days ago
Known vulnerabilities in the electron package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to NULL Pointer Dereference in the How to fix NULL Pointer Dereference? Upgrade | <39.8.5>=40.0.0-alpha.2 <40.8.5>=41.0.0-alpha.1 <41.1.0>=42.0.0-alpha.1 <42.0.0-alpha.5 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere via the How to fix Exposure of Resource to Wrong Sphere? Upgrade | <39.8.5>=40.0.0-alpha.2 <40.8.5>=41.0.0-alpha.1 <41.1.0>=42.0.0-alpha.1 <42.0.0-alpha.5 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Origin Validation Error in the Note: This is only exploitable if the application grants permissions based on the origin parameter or How to fix Origin Validation Error? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.1>=41.0.0-alpha.1 <41.0.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Command Injection in the Note: This is only exploitable if the application calls How to fix Command Injection? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.0>=41.0.0-alpha.1 <41.0.0-beta.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in the Note: This is only exploitable if the protocol name passed to How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.1>=41.0.0-alpha.1 <41.0.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free in the How to fix Use After Free? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.0>=41.0.0-alpha.1 <41.0.0-beta.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free in the download save dialog callback process. An attacker can cause a crash or memory corruption by triggering session destruction while a native save-file dialog is open and then dismissing the dialog. Note: This is only exploitable if the application allows downloads and programmatically destroys sessions at runtime. How to fix Use After Free? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.0>=40.0.0-alpha.2 <40.7.0>=41.0.0-alpha.1 <41.0.0-beta.7 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity via the Note: This is only exploitable if service workers are registered and the result of How to fix Insufficient Verification of Data Authenticity? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.1>=41.0.0-alpha.1 <41.0.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free via the Note: This is only exploitable if an asynchronous permission request handler is registered and invoked while the request is pending. How to fix Use After Free? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.0>=40.0.0-alpha.2 <40.7.0>=41.0.0-alpha.1 <41.0.0-beta.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Read in the Note: This is only exploitable if the application calls How to fix Out-of-bounds Read? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.1>=41.0.0-alpha.1 <41.0.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization in the handling of the Note: This is only exploitable if How to fix Improper Isolation or Compartmentalization? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.4>=40.0.0-alpha.2 <40.8.4>=41.0.0-alpha.1 <41.0.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Unquoted Search Path or Element in the Note: This is only exploitable if the application is installed in a non-standard location where ancestor directories are not protected against unauthorized writes. How to fix Unquoted Search Path or Element? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.1>=40.0.0-alpha.2 <40.8.0>=41.0.0-alpha.1 <41.0.0-beta.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Missing Authorization in the Note: This is only exploitable if the application implements unusual device-selection logic that can be manipulated. How to fix Missing Authorization? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.0>=40.0.0-alpha.2 <40.7.0>=41.0.0-alpha.1 <41.0.0-beta.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to HTTP Response Splitting via the Note: This is only exploitable if untrusted external input is reflected into response headers. How to fix HTTP Response Splitting? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.3>=40.0.0-alpha.2 <40.8.3>=41.0.0-alpha.1 <41.0.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free in the offscreen rendering process when a parent Note: This is only exploitable if offscreen rendering is enabled ( How to fix Use After Free? Upgrade | <39.8.1>=40.0.0-alpha.2 <40.7.0>=41.0.0-alpha.1 <41.0.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Hidden Functionality via the Note: This is only exploitable if external or untrusted input is used to construct How to fix Hidden Functionality? Upgrade | <38.8.6>=39.0.0-alpha.1 <39.8.0>=40.0.0-alpha.2 <40.7.0>=41.0.0-alpha.1 <41.0.0-beta.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Arbitrary Code Injection via modification of the Note: This is only exploitable if the application is launched from a filesystem to which the attacker has write access. How to fix Arbitrary Code Injection? Upgrade | <35.7.5>=36.0.0-alpha.1 <36.8.1>=37.0.0-alpha.1 <37.3.1>=38.0.0-alpha.1 <38.0.0-beta.6 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free via How to fix Use After Free? Upgrade | <37.2.6 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via the lack of limitation on max inlining ids in How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | <37.2.5 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via lack of support for escapes in How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | <37.2.5 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free via improper handling of possible socket destruction in How to fix Use After Free? Upgrade | <37.2.4 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Integer Overflow or Wraparound via an incorrect count being passed to How to fix Integer Overflow or Wraparound? Upgrade | <37.2.4 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Incorrect Calculation of Buffer Size via insufficient validation of untrusted input in How to fix Incorrect Calculation of Buffer Size? Upgrade | <37.2.4 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Function Call with Incorrectly Specified Arguments via an incorrect handle provided in unspecified circumstances in Mojo. An attacker can reflect a broker-initiated transport back to a broker, which ultimately allows for handle leaks if the reflected transport is later used to deserialize another transport containing handles. How to fix Function Call with Incorrectly Specified Arguments? Upgrade | <36.3.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Information Exposure via the How to fix Information Exposure? Upgrade | <36.3.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization that allows an attacker who can convince a user to follow a malicious link to escape sandbox protections, due to a logic error in the Mojo component. This vulnerability does not enable code execution on its own, but is presumed chainable with another vulnerability to achieve code execution and has been observed in the wild. Note: This vulnerability is only exploitable on Windows. How to fix Improper Isolation or Compartmentalization? Upgrade | <33.4.8>=34.0.0-alpha.1 <34.4.1>=35.0.0-alpha.1 <35.1.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') in v8. How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | <33.4.6>=34.0.0 <34.3.4 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free through the V8 engine. How to fix Use After Free? Upgrade | <32.3.3>=33.0.0-alpha.1 <33.4.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Heap-based Buffer Overflow in v8, when processing a very large number of parameters. How to fix Heap-based Buffer Overflow? Upgrade | <32.3.2>=33.0.0-alpha.1 <33.4.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free through the How to fix Use After Free? Upgrade | <33.4.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Write through crafted HTML pages. An attacker can exploit heap corruption by sending a specially crafted HTML page to the victim. How to fix Out-of-bounds Write? Upgrade | <32.3.2>=33.0.0-alpha.1 <33.4.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Write via a crafted HTML page. An attacker can potentially exploit heap corruption by sending a specially crafted HTML page to the victim. How to fix Out-of-bounds Write? Upgrade | <32.3.2>=33.0.0-alpha.1 <33.4.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to External Control of Assumed-Immutable Web Parameter due to an integer overflow in the How to fix External Control of Assumed-Immutable Web Parameter? Upgrade | >=32.0.0 <32.3.0>=33.0.0 <33.3.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Read through the How to fix Out-of-bounds Read? Upgrade | >=32.0.0 <32.3.0>=33.0.0 <33.3.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Write in V8. How to fix Out-of-bounds Write? Upgrade | >=32.0.0 <32.3.0>=33.0.0 <33.3.2 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Write through a crafted HTML page. An attacker can execute arbitrary code inside a sandbox by crafting malicious HTML content. How to fix Out-of-bounds Write? Upgrade | <32.3.0 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via a crafted HTML page. An attacker can potentially exploit object corruption by manipulating the HTML content. How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | >=31.0.0 <31.7.7>=32.0.0 <32.2.8 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access Restriction Bypass due to an inappropriate implementation in the How to fix Access Restriction Bypass? Upgrade | <31.7.5>=32.0.0-alpha.1 <32.2.5>=33.0.0 <33.2.1 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Use After Free via the How to fix Use After Free? Upgrade | <31.7.5>=32.0.0-alpha.1 <32.2.5 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via a crafted HTML page. An attacker can potentially exploit heap corruption. How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | <32.2.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Improper Access Control due to an inappropriate implementation in Extensions. An attacker can bypass site isolation. How to fix Improper Access Control? Upgrade | <31.7.4>=32.0.0 <32.2.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') via a crafted HTML page. An attacker can potentially exploit heap corruption. How to fix Access of Resource Using Incompatible Type ('Type Confusion')? Upgrade | <31.7.4>=32.0.0 <32.2.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Out-of-bounds Write in Dawn. How to fix Out-of-bounds Write? Upgrade | <31.7.4>=32.0.0 <32.2.3 |
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected versions of this package are vulnerable to Type Confusion in v8 engine. How to fix Type Confusion? Upgrade | <32.3.0 |