scientificlinux records
3 published records for vendor scientificlinux.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2014-3593No exploit | Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via scientificlinux · luci · CWE-94 | Medium6.0 | — | 1.4% | Oct 15, 2014 |
24Monitor | CVE-2013-4482No exploit | Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local userscientificlinux · luci | Medium6.2 | — | 0.4% | Nov 23, 2013 |
7Monitor | CVE-2013-4481No exploit | Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which ascientificlinux · luci · CWE-362 | Low1.9 | — | 0.2% | Nov 23, 2013 |
- CVE-2014-359324Monitor
Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via
MediumCVSS 6.0No exploitEPSS 1%scientificlinux · luciOct 15, 2014
- CVE-2013-448224Monitor
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local user
MediumCVSS 6.2No exploitEPSS 0%scientificlinux · luciNov 23, 2013
- CVE-2013-44817Monitor
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which a
LowCVSS 1.9No exploitEPSS 0%scientificlinux · luciNov 23, 2013