Записи intuit
16 опубликованных записей вендора intuit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-319 Cleartext Transmission of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2007-6387Proof of concept | Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics Ansintuit · bookkeeping · CWE-119 | Критическая9,3 | — | 38,0 % | 14 дек. 2007 г. |
39Наблюдать | CVE-2007-0322Эксплойта нет | Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arintuit · quickbooks · CWE-119 | Критическая9,3 | — | 6,0 % | 5 сент. 2007 г. |
39Наблюдать | CVE-2007-4471Эксплойта нет | Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or ointuit · quickbooks · CWE-22 | Критическая9,3 | — | 5,2 % | 5 сент. 2007 г. |
30Наблюдать | CVE-2018-11338Эксплойта нет | Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackintuit · lacerte · CWE-319 | Высокая7,5 | — | 0,9 % | 31 июл. 2018 г. |
28Наблюдать | CVE-2012-2418Эксплойта нет | Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll intuit · quickbooks · CWE-119 | Средняя6,8 | — | 3,2 % | 25 апр. 2012 г. |
28Наблюдать | CVE-2018-3854Эксплойта нет | An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5intuit · quicken 2018 · CWE-200 | Высокая7,1 | — | 0,4 % | 3 дек. 2018 г. |
27Наблюдать | CVE-2010-5198Эксплойта нет | Multiple untrusted search path vulnerabilities in Intuit QuickBooks 2010 allow local users to gain privileges via a Trojan horse (1) dbicudtintuit · quickbooks | Средняя6,9 | — | 0,3 % | 6 сент. 2012 г. |
23Наблюдать | CVE-2018-14833Эксплойта нет | Intuit Lacerte 2017 has Incorrect Access Control.intuit · lacerte · CWE-284 | Средняя5,9 | — | 1,2 % | 9 июл. 2019 г. |
18Наблюдать | CVE-2001-0465Эксплойта нет | TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow intuit · turbo tax | Средняя4,6 | — | 0,3 % | 18 июн. 2001 г. |
11Наблюдать | CVE-2012-2422Эксплойта нет | Intuit QuickBooks 2009 through 2012 might allow remote attackers to obtain pathname information via the qbwc://docontrol/GetCompanyFile funcintuit · quickbooks · CWE-200 | Низкая2,9 | — | 1,1 % | 25 апр. 2012 г. |
7Наблюдать | CVE-2012-2425Эксплойта нет | The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 throintuit · quickbooks · CWE-20 | Низкая1,8 | — | 1,3 % | 25 апр. 2012 г. |
7Наблюдать | CVE-2012-2420Эксплойта нет | The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 throintuit · quickbooks · CWE-200 | Низкая1,8 | — | 1,3 % | 25 апр. 2012 г. |
7Наблюдать | CVE-2012-2424Эксплойта нет | The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 throintuit · quickbooks | Низкая1,8 | — | 1,2 % | 25 апр. 2012 г. |
7Наблюдать | CVE-2012-2423Эксплойта нет | The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 throintuit · quickbooks · CWE-200 | Низкая1,8 | — | 1,1 % | 25 апр. 2012 г. |
7Наблюдать | CVE-2012-2419Эксплойта нет | Memory leak in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit Quickintuit · quickbooks · CWE-399 | Низкая1,8 | — | 1,0 % | 25 апр. 2012 г. |
7Наблюдать | CVE-2012-2421Эксплойта нет | Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggablePrintuit · quickbooks · CWE-22 | Низкая1,8 | — | 0,8 % | 25 апр. 2012 г. |
- CVE-2007-638748В плане
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics Ans
КритическаяCVSS 9,3Proof of conceptEPSS 38 %intuit · bookkeeping14 дек. 2007 г.
- CVE-2007-032239Наблюдать
Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute ar
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %intuit · quickbooks5 сент. 2007 г.
- CVE-2007-447139Наблюдать
Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or o
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %intuit · quickbooks5 сент. 2007 г.
- CVE-2018-1133830Наблюдать
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %intuit · lacerte31 июл. 2018 г.
- CVE-2012-241828Наблюдать
Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll
СредняяCVSS 6,8Эксплойта нетEPSS 3 %intuit · quickbooks25 апр. 2012 г.
- CVE-2018-385428Наблюдать
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %intuit · quicken 20183 дек. 2018 г.
- CVE-2010-519827Наблюдать
Multiple untrusted search path vulnerabilities in Intuit QuickBooks 2010 allow local users to gain privileges via a Trojan horse (1) dbicudt
СредняяCVSS 6,9Эксплойта нетEPSS 0 %intuit · quickbooks6 сент. 2012 г.
- CVE-2018-1483323Наблюдать
Intuit Lacerte 2017 has Incorrect Access Control.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %intuit · lacerte9 июл. 2019 г.
- CVE-2001-046518Наблюдать
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow
СредняяCVSS 4,6Эксплойта нетEPSS 0 %intuit · turbo tax18 июн. 2001 г.
- CVE-2012-242211Наблюдать
Intuit QuickBooks 2009 through 2012 might allow remote attackers to obtain pathname information via the qbwc://docontrol/GetCompanyFile func
НизкаяCVSS 2,9Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.
- CVE-2012-24257Наблюдать
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 thro
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.
- CVE-2012-24207Наблюдать
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 thro
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.
- CVE-2012-24247Наблюдать
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 thro
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.
- CVE-2012-24237Наблюдать
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 thro
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.
- CVE-2012-24197Наблюдать
Memory leak in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit Quick
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.
- CVE-2012-24217Наблюдать
Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggablePr
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %intuit · quickbooks25 апр. 2012 г.