deepin records
8 published records for vendor deepin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-269 Improper Privilege Management1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2017-7622No exploit | dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to deepin · deepin desktop environment · CWE-862 | High8.8 | — | 1.3% | Apr 10, 2017 |
32Monitor | CVE-2023-50254Proof of concept | Deepin Reader RCE vulnerability due to a design flawdeepin · deepin reader · CWE-22 | High7.8 | — | 2.1% | Dec 22, 2023 |
31Monitor | CVE-2023-50255No exploit | Zip Path Traversal in Deepin-Compressordeepin · deepin-compressor · CWE-22 | High7.8 | — | 1.1% | Dec 27, 2023 |
31Monitor | CVE-2023-50700No exploit | Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged uCWE-269 | High7.8 | — | 0.2% | Jul 26, 2024 |
28Monitor | CVE-2019-13226No exploit | deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() functideepin · deepin-clone · CWE-59 | High7.0 | — | 0.3% | Jul 4, 2019 |
22Monitor | CVE-2019-13229No exploit | deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, adeepin · deepin clone · CWE-59 | Medium5.5 | — | 0.4% | Jul 4, 2019 |
22Monitor | CVE-2019-13227No exploit | In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there.deepin · deepin-clone · CWE-59 | Medium5.5 | — | 0.4% | Jul 4, 2019 |
18Monitor | CVE-2019-13228No exploit | deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks thdeepin · deepin-clone · CWE-59 | Medium4.7 | — | 0.4% | Jul 4, 2019 |
- CVE-2017-762235Monitor
dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to
HighCVSS 8.8No exploitEPSS 1%deepin · deepin desktop environmentApr 10, 2017
- CVE-2023-5025432Monitor
Deepin Reader RCE vulnerability due to a design flaw
HighCVSS 7.8Proof of conceptEPSS 2%deepin · deepin readerDec 22, 2023
- CVE-2023-5025531Monitor
Zip Path Traversal in Deepin-Compressor
HighCVSS 7.8No exploitEPSS 1%deepin · deepin-compressorDec 27, 2023
- CVE-2023-5070031Monitor
Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged u
HighCVSS 7.8No exploitEPSS 0%Jul 26, 2024
- CVE-2019-1322628Monitor
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() functi
HighCVSS 7.0No exploitEPSS 0%deepin · deepin-cloneJul 4, 2019
- CVE-2019-1322922Monitor
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, a
MediumCVSS 5.5No exploitEPSS 0%deepin · deepin cloneJul 4, 2019
- CVE-2019-1322722Monitor
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there.
MediumCVSS 5.5No exploitEPSS 0%deepin · deepin-cloneJul 4, 2019
- CVE-2019-1322818Monitor
deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks th
MediumCVSS 4.7No exploitEPSS 0%deepin · deepin-cloneJul 4, 2019