pizzashack records
7 published records for vendor pizzashack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-134 Use of Externally-Controlled Format String1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-665 Improper Initialization1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-3463No exploit | Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict pizzashack · rssh · CWE-88 | Critical9.8 | — | 4.9% | Feb 6, 2019 |
40Plan | CVE-2019-3464No exploit | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shoupizzashack · rssh · CWE-665 | Critical9.8 | — | 4.7% | Feb 6, 2019 |
37Monitor | CVE-2004-1628No exploit | Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.pizzashack · rssh · CWE-134 | Critical9.0 | — | 4.7% | Oct 23, 2004 |
32Monitor | CVE-2019-1000018No exploit | rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in apizzashack · rssh · CWE-77 | High7.8 | — | 1.9% | Feb 4, 2019 |
17Monitor | CVE-2012-2252No exploit | Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restrictepizzashack · rssh | Medium4.4 | — | 0.4% | Jan 10, 2013 |
17Monitor | CVE-2012-2251No exploit | rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted sheldebian · debian linux · CWE-20 | Medium4.4 | — | 0.3% | Jan 10, 2013 |
8Monitor | CVE-2012-3478No exploit | rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line.pizzashack · rssh · CWE-264 | Low2.1 | — | 0.4% | Aug 31, 2012 |
- CVE-2019-346340Plan
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict
CriticalCVSS 9.8No exploitEPSS 5%pizzashack · rsshFeb 6, 2019
- CVE-2019-346440Plan
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shou
CriticalCVSS 9.8No exploitEPSS 5%pizzashack · rsshFeb 6, 2019
- CVE-2004-162837Monitor
Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.
CriticalCVSS 9.0No exploitEPSS 5%pizzashack · rsshOct 23, 2004
- CVE-2019-100001832Monitor
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in a
HighCVSS 7.8No exploitEPSS 2%pizzashack · rsshFeb 4, 2019
- CVE-2012-225217Monitor
Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricte
MediumCVSS 4.4No exploitEPSS 0%pizzashack · rsshJan 10, 2013
- CVE-2012-225117Monitor
rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shel
MediumCVSS 4.4No exploitEPSS 0%debian · debian linuxJan 10, 2013
- CVE-2012-34788Monitor
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line.
LowCVSS 2.1No exploitEPSS 0%pizzashack · rsshAug 31, 2012