Записи pizzashack
7 опубликованных записей вендора pizzashack.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-134 Use of Externally-Controlled Format String1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-665 Improper Initialization1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-3463Эксплойта нет | Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict pizzashack · rssh · CWE-88 | Критическая9,8 | — | 4,9 % | 6 февр. 2019 г. |
40В плане | CVE-2019-3464Эксплойта нет | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shoupizzashack · rssh · CWE-665 | Критическая9,8 | — | 4,7 % | 6 февр. 2019 г. |
37Наблюдать | CVE-2004-1628Эксплойта нет | Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.pizzashack · rssh · CWE-134 | Критическая9,0 | — | 4,7 % | 23 окт. 2004 г. |
32Наблюдать | CVE-2019-1000018Эксплойта нет | rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in apizzashack · rssh · CWE-77 | Высокая7,8 | — | 1,9 % | 4 февр. 2019 г. |
17Наблюдать | CVE-2012-2252Эксплойта нет | Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restrictepizzashack · rssh | Средняя4,4 | — | 0,4 % | 10 янв. 2013 г. |
17Наблюдать | CVE-2012-2251Эксплойта нет | rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted sheldebian · debian linux · CWE-20 | Средняя4,4 | — | 0,3 % | 10 янв. 2013 г. |
8Наблюдать | CVE-2012-3478Эксплойта нет | rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line.pizzashack · rssh · CWE-264 | Низкая2,1 | — | 0,4 % | 31 авг. 2012 г. |
- CVE-2019-346340В плане
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pizzashack · rssh6 февр. 2019 г.
- CVE-2019-346440В плане
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shou
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pizzashack · rssh6 февр. 2019 г.
- CVE-2004-162837Наблюдать
Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.
КритическаяCVSS 9,0Эксплойта нетEPSS 5 %pizzashack · rssh23 окт. 2004 г.
- CVE-2019-100001832Наблюдать
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %pizzashack · rssh4 февр. 2019 г.
- CVE-2012-225217Наблюдать
Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricte
СредняяCVSS 4,4Эксплойта нетEPSS 0 %pizzashack · rssh10 янв. 2013 г.
- CVE-2012-225117Наблюдать
rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shel
СредняяCVSS 4,4Эксплойта нетEPSS 0 %debian · debian linux10 янв. 2013 г.
- CVE-2012-34788Наблюдать
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pizzashack · rssh31 авг. 2012 г.