Записи call-cc
21 опубликованных записей вендора call-cc.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 76,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-20 Improper Input Validation4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-19 Data Processing Errors2
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-6310Эксплойта нет | Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.call-cc · chicken · CWE-120 | Критическая9,8 | — | 4,7 % | 22 нояб. 2019 г. |
40В плане | CVE-2016-6830Эксплойта нет | The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment varcall-cc · chicken · CWE-119 | Критическая9,8 | — | 2,1 % | 10 янв. 2017 г. |
40В плане | CVE-2012-6125Эксплойта нет | Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.call-cc · chicken · CWE-20 | Критическая9,8 | — | 1,8 % | 31 окт. 2019 г. |
39Наблюдать | CVE-2022-45145Эксплойта нет | egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egcall-cc · chicken · CWE-78 | Критическая9,8 | — | 1,3 % | 10 дек. 2022 г. |
36Наблюдать | CVE-2013-2024Эксплойта нет | OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.call-cc · chicken · CWE-78 | Высокая8,8 | — | 4,5 % | 31 окт. 2019 г. |
36Наблюдать | CVE-2013-2075Эксплойта нет | Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allowscall-cc · chicken · CWE-120 | Высокая8,8 | — | 2,2 % | 31 окт. 2019 г. |
32Наблюдать | CVE-2017-6949Эксплойта нет | An issue was discovered in CHICKEN Scheme through 4.12.0.call-cc · chicken · CWE-119 | Высокая8,1 | — | 1,5 % | 16 мар. 2017 г. |
31Наблюдать | CVE-2014-3776Эксплойта нет | Buffer overflow in the "read-u8vector!" procedure in the srfi-4 unit in CHICKEN stable 4.8.0.7 and development snapshots before 4.9.1 allowscall-cc · chicken · CWE-119 | Высокая7,5 | — | 4,5 % | 20 мая 2014 г. |
31Наблюдать | CVE-2013-4385Эксплойта нет | Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3call-cc · chicken · CWE-119 | Высокая7,5 | — | 3,4 % | 9 окт. 2013 г. |
31Наблюдать | CVE-2015-8235Эксплойта нет | Directory traversal vulnerability in Spiffy before 5.4.call-cc · spiffy · CWE-22 | Высокая7,5 | — | 3,1 % | 7 июн. 2017 г. |
31Наблюдать | CVE-2012-6122Эксплойта нет | Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file decall-cc · chicken · CWE-120 | Высокая7,5 | — | 2,2 % | 31 окт. 2019 г. |
31Наблюдать | CVE-2015-4556Эксплойта нет | The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (ccall-cc · chicken · CWE-20 | Высокая7,5 | — | 2,1 % | 29 мар. 2017 г. |
31Наблюдать | CVE-2016-6831Эксплойта нет | The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leakcall-cc · chicken · CWE-400 | Высокая7,5 | — | 1,8 % | 10 янв. 2017 г. |
30Наблюдать | CVE-2017-9334Эксплойта нет | An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior tocall-cc · chicken · CWE-20 | Высокая7,5 | — | 1,5 % | 1 июн. 2017 г. |
30Наблюдать | CVE-2016-6286Эксплойта нет | The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackerscall-cc · http-client · CWE-19 | Высокая7,5 | — | 1,5 % | 10 янв. 2017 г. |
30Наблюдать | CVE-2016-6287Эксплойта нет | The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even whecall-cc · http-client · CWE-19 | Высокая7,5 | — | 1,5 % | 10 янв. 2017 г. |
30Наблюдать | CVE-2014-9651Эксплойта нет | Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a posicall-cc · chicken · CWE-119 | Высокая7,5 | — | 1,5 % | 28 авг. 2015 г. |
30Наблюдать | CVE-2017-11343Эксплойта нет | Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complcall-cc · chicken · CWE-407 | Высокая7,5 | — | 0,9 % | 17 июл. 2017 г. |
26Наблюдать | CVE-2012-6123Эксплойта нет | Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."call-cc · chicken · CWE-20 | Средняя6,5 | — | 1,3 % | 31 окт. 2019 г. |
21Наблюдать | CVE-2012-6124Эксплойта нет | A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value.call-cc · chicken · CWE-338 | Средняя5,3 | — | 1,3 % | 31 окт. 2019 г. |
17Наблюдать | CVE-2013-1874Эксплойта нет | Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Trojan horse .csirc incall-cc · chicken | Средняя4,4 | — | 0,4 % | 29 сент. 2014 г. |
- CVE-2014-631040В плане
Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %call-cc · chicken22 нояб. 2019 г.
- CVE-2016-683040В плане
The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment var
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %call-cc · chicken10 янв. 2017 г.
- CVE-2012-612540В плане
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %call-cc · chicken31 окт. 2019 г.
- CVE-2022-4514539Наблюдать
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .eg
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %call-cc · chicken10 дек. 2022 г.
- CVE-2013-202436Наблюдать
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %call-cc · chicken31 окт. 2019 г.
- CVE-2013-207536Наблюдать
Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %call-cc · chicken31 окт. 2019 г.
- CVE-2017-694932Наблюдать
An issue was discovered in CHICKEN Scheme through 4.12.0.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %call-cc · chicken16 мар. 2017 г.
- CVE-2014-377631Наблюдать
Buffer overflow in the "read-u8vector!" procedure in the srfi-4 unit in CHICKEN stable 4.8.0.7 and development snapshots before 4.9.1 allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %call-cc · chicken20 мая 2014 г.
- CVE-2013-438531Наблюдать
Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %call-cc · chicken9 окт. 2013 г.
- CVE-2015-823531Наблюдать
Directory traversal vulnerability in Spiffy before 5.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %call-cc · spiffy7 июн. 2017 г.
- CVE-2012-612231Наблюдать
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file de
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %call-cc · chicken31 окт. 2019 г.
- CVE-2015-455631Наблюдать
The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (c
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %call-cc · chicken29 мар. 2017 г.
- CVE-2016-683131Наблюдать
The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %call-cc · chicken10 янв. 2017 г.
- CVE-2017-933430Наблюдать
An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %call-cc · chicken1 июн. 2017 г.
- CVE-2016-628630Наблюдать
The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %call-cc · http-client10 янв. 2017 г.
- CVE-2016-628730Наблюдать
The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even whe
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %call-cc · http-client10 янв. 2017 г.
- CVE-2014-965130Наблюдать
Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a posi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %call-cc · chicken28 авг. 2015 г.
- CVE-2017-1134330Наблюдать
Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic compl
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %call-cc · chicken17 июл. 2017 г.
- CVE-2012-612326Наблюдать
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
СредняяCVSS 6,5Эксплойта нетEPSS 1 %call-cc · chicken31 окт. 2019 г.
- CVE-2012-612421Наблюдать
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %call-cc · chicken31 окт. 2019 г.
- CVE-2013-187417Наблюдать
Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Trojan horse .csirc in
СредняяCVSS 4,4Эксплойта нетEPSS 0 %call-cc · chicken29 сент. 2014 г.