ebay records
4 published records for vendor ebay.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2008-2475No exploit | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via tebay · enhanced picture uploader activex control · CWE-78 | Critical9.3 | — | 4.1% | Jun 9, 2009 |
31Monitor | CVE-2006-1176No exploit | Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Iteebay · enhanced picture services | High7.5 | — | 4.6% | Jul 7, 2006 |
31Monitor | CVE-2023-26107No exploit | All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametriebay · sketchsvg · CWE-94 | High7.8 | — | 0.4% | Mar 6, 2023 |
11Monitor | CVE-2010-4211No exploit | The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate,ebay · paypal · CWE-287 | Low2.9 | — | 0.4% | Nov 8, 2010 |
- CVE-2008-247538Monitor
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via t
CriticalCVSS 9.3No exploitEPSS 4%ebay · enhanced picture uploader activex controlJun 9, 2009
- CVE-2006-117631Monitor
Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Ite
HighCVSS 7.5No exploitEPSS 5%ebay · enhanced picture servicesJul 7, 2006
- CVE-2023-2610731Monitor
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametri
HighCVSS 7.8No exploitEPSS 0%ebay · sketchsvgMar 6, 2023
- CVE-2010-421111Monitor
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate,
LowCVSS 2.9No exploitEPSS 0%ebay · paypalNov 8, 2010