Phusion kayıtları
phusion üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %92,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-908 Use of Uninitialized Resource1
- CWE-255 Credentials Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-12026İstismar yok | During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applicatiophusion · passenger · CWE-59 | Kritik9,8 | — | %1,9 | 17 Haz 2018 |
35İzleyin | CVE-2018-12027İstismar yok | An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following phusion · passenger · CWE-200 | Yüksek8,8 | — | %1,1 | 17 Haz 2018 |
31İzleyin | CVE-2013-7134İstismar yok | Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key phusion · juvia · CWE-255 | Yüksek7,5 | — | %2,3 | 29 Nis 2014 |
31İzleyin | CVE-2012-6135İstismar yok | RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.phusion · passenger · CWE-20 | Yüksek7,5 | — | %2,3 | 19 Kas 2019 |
31İzleyin | CVE-2018-12028İstismar yok | An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious applicphusion · passenger · CWE-732 | Yüksek7,8 | — | %0,9 | 17 Haz 2018 |
31İzleyin | CVE-2016-10345İstismar yok | In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local aphusion · passenger · CWE-264 | Yüksek7,8 | — | %0,5 | 18 Nis 2017 |
30İzleyin | CVE-2025-26803İstismar yok | The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invaphusion · passenger · CWE-908 | Yüksek7,5 | — | %0,6 | 24 Şub 2025 |
28İzleyin | CVE-2018-12029İstismar yok | A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-stanphusion · passenger · CWE-362 | Yüksek7,0 | — | %0,3 | 17 Haz 2018 |
21İzleyin | CVE-2018-12615İstismar yok | An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2.phusion · passenger · CWE-732 | Orta5,3 | — | %1,2 | 21 Haz 2018 |
18İzleyin | CVE-2013-2119İstismar yok | Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application staphusion · passenger · CWE-264 | Orta4,6 | — | %0,4 | 3 Oca 2014 |
18İzleyin | CVE-2017-16355İstismar yok | In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if phusion · passenger · CWE-200 | Orta4,7 | — | %0,4 | 14 Ara 2017 |
17İzleyin | CVE-2013-4136İstismar yok | ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ophusion · passenger · CWE-59 | Orta4,4 | — | %0,3 | 30 Eyl 2013 |
8İzleyin | CVE-2014-1831İstismar yok | Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pidphusion · passenger | Düşük2,1 | — | %0,4 | 19 Şub 2015 |
8İzleyin | CVE-2014-1832İstismar yok | Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (phusion · passenger | Düşük2,1 | — | %0,4 | 19 Şub 2015 |
- CVE-2018-1202640Planlayın
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applicatio
KritikCVSS 9,8İstismar yokEPSS %2phusion · passenger17 Haz 2018
- CVE-2018-1202735İzleyin
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following
YüksekCVSS 8,8İstismar yokEPSS %1phusion · passenger17 Haz 2018
- CVE-2013-713431İzleyin
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key
YüksekCVSS 7,5İstismar yokEPSS %2phusion · juvia29 Nis 2014
- CVE-2012-613531İzleyin
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
YüksekCVSS 7,5İstismar yokEPSS %2phusion · passenger19 Kas 2019
- CVE-2018-1202831İzleyin
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious applic
YüksekCVSS 7,8İstismar yokEPSS %1phusion · passenger17 Haz 2018
- CVE-2016-1034531İzleyin
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local a
YüksekCVSS 7,8İstismar yokEPSS %0phusion · passenger18 Nis 2017
- CVE-2025-2680330İzleyin
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an inva
YüksekCVSS 7,5İstismar yokEPSS %1phusion · passenger24 Şub 2025
- CVE-2018-1202928İzleyin
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-stan
YüksekCVSS 7,0İstismar yokEPSS %0phusion · passenger17 Haz 2018
- CVE-2018-1261521İzleyin
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2.
OrtaCVSS 5,3İstismar yokEPSS %1phusion · passenger21 Haz 2018
- CVE-2013-211918İzleyin
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application sta
OrtaCVSS 4,6İstismar yokEPSS %0phusion · passenger3 Oca 2014
- CVE-2017-1635518İzleyin
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if
OrtaCVSS 4,7İstismar yokEPSS %0phusion · passenger14 Ara 2017
- CVE-2013-413617İzleyin
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the o
OrtaCVSS 4,4İstismar yokEPSS %0phusion · passenger30 Eyl 2013
- CVE-2014-18318İzleyin
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid
DüşükCVSS 2,1İstismar yokEPSS %0phusion · passenger19 Şub 2015
- CVE-2014-18328İzleyin
Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (
DüşükCVSS 2,1İstismar yokEPSS %0phusion · passenger19 Şub 2015