radicale kayıtları
radicale üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-21 DEPRECATED: Pathname Traversal and Equivalence Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2015-8747İstismar yok | The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted componeradicale · radicale · CWE-20 | Kritik10,0 | — | %3,0 | 3 Şub 2016 |
41Planlayın | CVE-2016-1505İstismar yok | The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted pradicale · radicale · CWE-21 | Kritik10,0 | — | %2,6 | 3 Şub 2016 |
33İzleyin | CVE-2017-8342İstismar yok | Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authenticatiradicale · radicale · CWE-362 | Yüksek8,1 | — | %2,0 | 30 Nis 2017 |
22İzleyin | CVE-2015-8748İstismar yok | Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user radicale · radicale · CWE-264 | Orta5,3 | — | %2,2 | 3 Şub 2016 |
- CVE-2015-874741Planlayın
The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted compone
KritikCVSS 10,0İstismar yokEPSS %3radicale · radicale3 Şub 2016
- CVE-2016-150541Planlayın
The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted p
KritikCVSS 10,0İstismar yokEPSS %3radicale · radicale3 Şub 2016
- CVE-2017-834233İzleyin
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authenticati
YüksekCVSS 8,1İstismar yokEPSS %2radicale · radicale30 Nis 2017
- CVE-2015-874822İzleyin
Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user
OrtaCVSS 5,3İstismar yokEPSS %2radicale · radicale3 Şub 2016