pippo kayıtları
pippo üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %80
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data2
- CWE-20 Improper Input Validation1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2017-18349Kavram kanıtı | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbipippo · pippo · CWE-20 | Kritik9,8 | — | %39,2 | 23 Eki 2018 |
41Planlayın | CVE-2018-18628İstismar yok | An issue was discovered in Pippo 1.11.0.pippo · pippo · CWE-502 | Kritik9,8 | — | %5,5 | 23 Eki 2018 |
40Planlayın | CVE-2018-18240İstismar yok | Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not usepippo · pippo · CWE-502 | Kritik9,8 | — | %3,7 | 11 Eki 2018 |
39İzleyin | CVE-2018-20059İstismar yok | jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.pippo · pippo · CWE-611 | Kritik9,8 | — | %1,5 | 11 Ara 2018 |
30İzleyin | CVE-2019-5442İstismar yok | XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amountspippo · pippo · CWE-776 | Yüksek7,5 | — | %1,4 | 12 Haz 2019 |
- CVE-2017-1834951Planlayın
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbi
KritikCVSS 9,8Kavram kanıtıEPSS %39pippo · pippo23 Eki 2018
- CVE-2018-1862841Planlayın
An issue was discovered in Pippo 1.11.0.
KritikCVSS 9,8İstismar yokEPSS %5pippo · pippo23 Eki 2018
- CVE-2018-1824040Planlayın
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use
KritikCVSS 9,8İstismar yokEPSS %4pippo · pippo11 Eki 2018
- CVE-2018-2005939İzleyin
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
KritikCVSS 9,8İstismar yokEPSS %2pippo · pippo11 Ara 2018
- CVE-2019-544230İzleyin
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts
YüksekCVSS 7,5İstismar yokEPSS %1pippo · pippo12 Haz 2019