Записи fishshell
7 опубликованных записей вендора fishshell.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-436 Interpretation Conflict1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-2914Эксплойта нет | fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackfishshell · fish · CWE-20 | Критическая9,8 | — | 3,2 % | 28 янв. 2020 г. |
31Наблюдать | CVE-2022-20001Эксплойта нет | fish is a command line shell.fishshell · fish · CWE-74 | Высокая7,8 | — | 1,5 % | 14 мар. 2022 г. |
31Наблюдать | CVE-2014-3219Эксплойта нет | fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (fishshell · fish · CWE-59 | Высокая7,8 | — | 0,4 % | 9 февр. 2018 г. |
28Наблюдать | CVE-2014-2906Эксплойта нет | The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to executefishshell · fish · CWE-362 | Высокая7,0 | — | 0,3 % | 28 янв. 2020 г. |
28Наблюдать | CVE-2014-3856Эксплойта нет | The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain fishshell · fish · CWE-362 | Высокая7,0 | — | 0,3 % | 28 янв. 2020 г. |
27Наблюдать | CVE-2014-2905Эксплойта нет | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the univefishshell · fish · CWE-264 | Средняя6,9 | — | 0,4 % | 2 мая 2014 г. |
26Наблюдать | CVE-2023-49284Эксплойта нет | Command substitution output can trigger shell expansion in fish shellfishshell · fish · CWE-436 | Средняя6,6 | — | 0,5 % | 4 дек. 2023 г. |
- CVE-2014-291440В плане
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attack
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %fishshell · fish28 янв. 2020 г.
- CVE-2022-2000131Наблюдать
fish is a command line shell.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %fishshell · fish14 мар. 2022 г.
- CVE-2014-321931Наблюдать
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %fishshell · fish9 февр. 2018 г.
- CVE-2014-290628Наблюдать
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %fishshell · fish28 янв. 2020 г.
- CVE-2014-385628Наблюдать
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %fishshell · fish28 янв. 2020 г.
- CVE-2014-290527Наблюдать
fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the unive
СредняяCVSS 6,9Эксплойта нетEPSS 0 %fishshell · fish2 мая 2014 г.
- CVE-2023-4928426Наблюдать
Command substitution output can trigger shell expansion in fish shell
СредняяCVSS 6,6Эксплойта нетEPSS 0 %fishshell · fish4 дек. 2023 г.