Записи attachmate
10 опубликованных записей вендора attachmate.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2011-5012Proof of concept | Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflectioattachmate · reflection · CWE-119 | Критическая10,0 | — | 7,8 % | 24 дек. 2011 г. |
42В плане | CVE-2014-0605Эксплойта нет | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attacattachmate · reflection ftp client · CWE-22 | Критическая10,0 | — | 7,7 % | 6 февр. 2015 г. |
42В плане | CVE-2014-0604Эксплойта нет | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attacattachmate · reflection ftp client · CWE-22 | Критическая10,0 | — | 6,3 % | 6 февр. 2015 г. |
42В плане | CVE-2014-0603Эксплойта нет | The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (meattachmate · reflection ftp client · CWE-94 | Критическая10,0 | — | 5,7 % | 6 февр. 2015 г. |
41В плане | CVE-2014-0607Эксплойта нет | Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to exeattachmate · verastream process designer | Критическая10,0 | — | 3,4 % | 24 июл. 2014 г. |
41В плане | CVE-2008-6021Эксплойта нет | Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and atattachmate · reflection for secure it | Критическая10,0 | — | 1,9 % | 2 февр. 2009 г. |
38Наблюдать | CVE-2013-3626Эксплойта нет | Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remoattachmate · verastream host integrator · CWE-22 | Критическая9,3 | — | 2,8 % | 6 нояб. 2013 г. |
28Наблюдать | CVE-2014-5211Эксплойта нет | Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via attachmate · reflection ftp client · CWE-119 | Средняя6,8 | — | 2,8 % | 27 янв. 2015 г. |
27Наблюдать | CVE-2011-5157Эксплойта нет | Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL inattachmate · reflection for hp | Средняя6,9 | — | 0,4 % | 6 сент. 2012 г. |
17Наблюдать | CVE-2010-4146Эксплойта нет | Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and eaattachmate · reflection for the web · CWE-79 | Средняя4,3 | — | 1,1 % | 1 нояб. 2010 г. |
- CVE-2011-501242В плане
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflectio
КритическаяCVSS 10,0Proof of conceptEPSS 8 %attachmate · reflection24 дек. 2011 г.
- CVE-2014-060542В плане
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attac
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %attachmate · reflection ftp client6 февр. 2015 г.
- CVE-2014-060442В плане
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attac
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %attachmate · reflection ftp client6 февр. 2015 г.
- CVE-2014-060342В плане
The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (me
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %attachmate · reflection ftp client6 февр. 2015 г.
- CVE-2014-060741В плане
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to exe
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %attachmate · verastream process designer24 июл. 2014 г.
- CVE-2008-602141В плане
Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and at
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %attachmate · reflection for secure it2 февр. 2009 г.
- CVE-2013-362638Наблюдать
Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remo
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %attachmate · verastream host integrator6 нояб. 2013 г.
- CVE-2014-521128Наблюдать
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via
СредняяCVSS 6,8Эксплойта нетEPSS 3 %attachmate · reflection ftp client27 янв. 2015 г.
- CVE-2011-515727Наблюдать
Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in
СредняяCVSS 6,9Эксплойта нетEPSS 0 %attachmate · reflection for hp6 сент. 2012 г.
- CVE-2010-414617Наблюдать
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and ea
СредняяCVSS 4,3Эксплойта нетEPSS 1 %attachmate · reflection for the web1 нояб. 2010 г.