A logical vulnerability in OpenPGP.js, allowing for spoofed signatures using a crafted PGP packet sequence
A logical vulnerability in OpenPGP.js, allowing for spoofed signatures using a crafted PGP packet sequence
A fully playable Tetris game embedded in a PDF file, using JavaScript and PDF form fields.
A bunch of bugs in Ghostscript, including a classic format string vulnerability leading to RCE
A bug in PDF.js (and Firefox) with widespread XSS consequences
Write-up on several bugs in Feathers.js, Sequelize, and Socket.IO relating to type confusion and incorrect interop assumptions