The Tag Project maintains a narrowly scoped tagging utility that, despite a minimal disclosure footprint, serves a role in software ecosystems where it is more prominent than typical vulnerability volumes would suggest. The disclosed vulnerabilities center on improper array-index validation, a characteristic input-handling weakness in utilities that parse and process structured data. Current severity, exploitation status, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tag Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29245MEDIUM dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData. | Dec 28, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-29244MEDIUM dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame. | Dec 28, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-29243MEDIUM dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame. | Dec 28, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-29242MEDIUM dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame. | Dec 28, 2020 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tag Project.
Media articles that mention a CVE ID that affects a product developed by Tag Project — matched by CVE ID, not by vendor name.