rpcbind project records
4 published records for vendor rpcbind project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 25%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2017-8779Weaponized | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data rpcbind project · rpcbind · CWE-770 | High7.5 | — | 81.2% | May 4, 2017 |
32Monitor | CVE-2015-7236No exploit | Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of rpcbind project · rpcbind | High7.5 | — | 6.4% | Oct 1, 2015 |
31Monitor | CVE-2010-2061No exploit | rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemorpcbind project · rpcbind · CWE-20 | High7.8 | — | 0.4% | Oct 29, 2019 |
28Monitor | CVE-2010-2064No exploit | rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rprpcbind project · rpcbind · CWE-59 | High7.1 | — | 0.4% | Oct 29, 2019 |
- CVE-2017-877954Plan
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data
HighCVSS 7.5WeaponizedEPSS 81%rpcbind project · rpcbindMay 4, 2017
- CVE-2015-723632Monitor
Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of
HighCVSS 7.5No exploitEPSS 6%rpcbind project · rpcbindOct 1, 2015
- CVE-2010-206131Monitor
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemo
HighCVSS 7.8No exploitEPSS 0%rpcbind project · rpcbindOct 29, 2019
- CVE-2010-206428Monitor
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rp
HighCVSS 7.1No exploitEPSS 0%rpcbind project · rpcbindOct 29, 2019