Записи lhaplus
8 опубликованных записей вендора lhaplus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2007-5048Эксплойта нет | Heap-based buffer overflow in Lhaplus before 1.55 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.lhaplus · lhaplus · CWE-119 | Высокая7,5 | — | 4,1 % | 23 сент. 2007 г. |
31Наблюдать | CVE-2008-2021Эксплойта нет | Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archivlhaplus · lhaplus · CWE-119 | Высокая7,5 | — | 3,5 % | 30 апр. 2008 г. |
28Наблюдать | CVE-2015-0907Эксплойта нет | Buffer overflow in Lhaplus before 1.70 allows remote attackers to execute arbitrary code via a crafted archive.lhaplus · lhaplus · CWE-119 | Средняя6,8 | — | 2,7 % | 15 апр. 2015 г. |
27Наблюдать | CVE-2007-6175Эксплойта нет | Buffer overflow in Lhaplus 1.55 and earlier allows remote attackers to execute arbitrary code via a crafted LZH archive, a different vector lhaplus · lhaplus · CWE-119 | Средняя6,6 | — | 3,5 % | 29 нояб. 2007 г. |
27Наблюдать | CVE-2010-2368Эксплойта нет | Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse DLL in the current workilhaplus · lhaplus | Средняя6,9 | — | 0,3 % | 18 окт. 2010 г. |
27Наблюдать | CVE-2010-3158Эксплойта нет | Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse executable file in the clhaplus · lhaplus | Средняя6,9 | — | 0,3 % | 19 окт. 2010 г. |
23Наблюдать | CVE-2015-0906Эксплойта нет | Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.lhaplus · lhaplus · CWE-22 | Средняя5,8 | — | 1,5 % | 15 апр. 2015 г. |
22Наблюдать | CVE-2006-4033Эксплойта нет | Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code lhaplus · lhaplus | Средняя5,1 | — | 5,0 % | 9 авг. 2006 г. |
- CVE-2007-504831Наблюдать
Heap-based buffer overflow in Lhaplus before 1.55 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %lhaplus · lhaplus23 сент. 2007 г.
- CVE-2008-202131Наблюдать
Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archiv
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lhaplus · lhaplus30 апр. 2008 г.
- CVE-2015-090728Наблюдать
Buffer overflow in Lhaplus before 1.70 allows remote attackers to execute arbitrary code via a crafted archive.
СредняяCVSS 6,8Эксплойта нетEPSS 3 %lhaplus · lhaplus15 апр. 2015 г.
- CVE-2007-617527Наблюдать
Buffer overflow in Lhaplus 1.55 and earlier allows remote attackers to execute arbitrary code via a crafted LZH archive, a different vector
СредняяCVSS 6,6Эксплойта нетEPSS 3 %lhaplus · lhaplus29 нояб. 2007 г.
- CVE-2010-236827Наблюдать
Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse DLL in the current worki
СредняяCVSS 6,9Эксплойта нетEPSS 0 %lhaplus · lhaplus18 окт. 2010 г.
- CVE-2010-315827Наблюдать
Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse executable file in the c
СредняяCVSS 6,9Эксплойта нетEPSS 0 %lhaplus · lhaplus19 окт. 2010 г.
- CVE-2015-090623Наблюдать
Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.
СредняяCVSS 5,8Эксплойта нетEPSS 2 %lhaplus · lhaplus15 апр. 2015 г.
- CVE-2006-403322Наблюдать
Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code
СредняяCVSS 5,1Эксплойта нетEPSS 5 %lhaplus · lhaplus9 авг. 2006 г.