feep kayıtları
feep üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read2
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-189 Numeric Errors1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2021-33643İstismar yok | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable feep · libtar · CWE-125 | Kritik9,1 | — | %1,7 | 10 Ağu 2022 |
32İzleyin | CVE-2021-33644İstismar yok | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable feep · libtar · CWE-125 | Yüksek8,1 | — | %1,4 | 10 Ağu 2022 |
31İzleyin | CVE-2021-33645İstismar yok | The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.feep · libtar · CWE-401 | Yüksek7,5 | — | %1,8 | 10 Ağu 2022 |
31İzleyin | CVE-2021-33646İstismar yok | The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.feep · libtar · CWE-401 | Yüksek7,5 | — | %1,8 | 10 Ağu 2022 |
29İzleyin | CVE-2013-4397İstismar yok | Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of servicredhat · enterprise linux · CWE-189 | Orta6,8 | — | %5,5 | 17 Eki 2013 |
24İzleyin | CVE-2013-4420İstismar yok | Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allofeep · libtar · CWE-22 | Orta5,8 | — | %3,3 | 20 Şub 2014 |
- CVE-2021-3364336İzleyin
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable
KritikCVSS 9,1İstismar yokEPSS %2feep · libtar10 Ağu 2022
- CVE-2021-3364432İzleyin
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable
YüksekCVSS 8,1İstismar yokEPSS %1feep · libtar10 Ağu 2022
- CVE-2021-3364531İzleyin
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
YüksekCVSS 7,5İstismar yokEPSS %2feep · libtar10 Ağu 2022
- CVE-2021-3364631İzleyin
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
YüksekCVSS 7,5İstismar yokEPSS %2feep · libtar10 Ağu 2022
- CVE-2013-439729İzleyin
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of servic
OrtaCVSS 6,8İstismar yokEPSS %5redhat · enterprise linux17 Eki 2013
- CVE-2013-442024İzleyin
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allo
OrtaCVSS 5,8İstismar yokEPSS %3feep · libtar20 Şub 2014