Записи badblue
4 опубликованных записей вендора badblue.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 25 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-16 Configuration1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2007-6377Готовый эксплойт | Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrabadblue · badblue · CWE-119 | Высокая7,5 | — | 66,4 % | 14 дек. 2007 г. |
31Наблюдать | CVE-2007-6378Proof of concept | Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files badblue · badblue · CWE-22 | Высокая7,5 | — | 3,2 % | 14 дек. 2007 г. |
31Наблюдать | CVE-2008-2003Эксплойта нет | BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackbadblue · badblue · CWE-264 | Высокая7,5 | — | 2,8 % | 28 апр. 2008 г. |
21Наблюдать | CVE-2007-6379Proof of concept | BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installbadblue · badblue · CWE-16 | Средняя5,0 | — | 3,3 % | 14 дек. 2007 г. |
- CVE-2007-637750В плане
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitra
ВысокаяCVSS 7,5Готовый эксплойтEPSS 66 %badblue · badblue14 дек. 2007 г.
- CVE-2007-637831Наблюдать
Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %badblue · badblue14 дек. 2007 г.
- CVE-2008-200331Наблюдать
BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %badblue · badblue28 апр. 2008 г.
- CVE-2007-637921Наблюдать
BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the install
СредняяCVSS 5,0Proof of conceptEPSS 3 %badblue · badblue14 дек. 2007 г.