Записи conectiva
66 опубликованных записей вендора conectiva.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 22
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-399 Resource Management Errors2
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
66 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2003-0780Proof of concept | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privilmysql · mysql | Критическая9,0 | — | 78,4 % | 22 сент. 2003 г. |
48В плане | CVE-2000-0666Proof of concept | rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote atconectiva · linux | Критическая10,0 | — | 26,3 % | 16 июл. 2000 г. |
48В плане | CVE-2004-0557Proof of concept | Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers tsox · sox | Критическая10,0 | — | 25,1 % | 6 авг. 2004 г. |
45В плане | CVE-2000-0844Proof of concept | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackecaldera · openlinux ebuilder · CWE-264 | Критическая10,0 | — | 15,6 % | 14 нояб. 2000 г. |
44В плане | CVE-2004-0882Эксплойта нет | Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via asamba · samba | Критическая10,0 | — | 13,7 % | 27 янв. 2005 г. |
43В плане | CVE-2002-0083Proof of concept | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Критическая9,8 | — | 14,7 % | 15 мар. 2002 г. |
43В плане | CVE-2004-0902Эксплойта нет | Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow rmozilla · mozilla | Критическая10,0 | — | 10,1 % | 27 янв. 2005 г. |
43В плане | CVE-2004-0903Эксплойта нет | Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.mozilla · mozilla | Критическая10,0 | — | 9,7 % | 27 янв. 2005 г. |
42В плане | CVE-2004-1029Proof of concept | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restsun · jdk · CWE-264 | Критическая9,3 | — | 17,0 % | 1 мар. 2005 г. |
42В плане | CVE-2004-0904Эксплойта нет | Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.mozilla · firefox | Критическая10,0 | — | 8,0 % | 31 дек. 2004 г. |
42В плане | CVE-2004-1012Эксплойта нет | The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Критическая10,0 | — | 6,0 % | 10 янв. 2005 г. |
42В плане | CVE-2004-1011Эксплойта нет | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execcarnegie mellon university · cyrus imap server | Критическая10,0 | — | 5,8 % | 10 янв. 2005 г. |
42В плане | CVE-2004-1013Эксплойта нет | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Критическая10,0 | — | 5,8 % | 10 янв. 2005 г. |
41В плане | CVE-2005-3625Эксплойта нет | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Критическая10,0 | — | 3,8 % | 31 дек. 2005 г. |
41В плане | CVE-2000-0747Эксплойта нет | The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.conectiva · linux | Критическая10,0 | — | 1,7 % | 20 окт. 2000 г. |
34Наблюдать | CVE-2001-0690Proof of concept | Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attackerconectiva · linux | Высокая7,5 | — | 11,9 % | 20 сент. 2001 г. |
33Наблюдать | CVE-2001-0136Proof of concept | Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commanproftpd · proftpd · CWE-401 | Средняя5,0 | — | 44,9 % | 12 мар. 2001 г. |
32Наблюдать | CVE-2005-0699Эксплойта нет | Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and eaethereal group · ethereal | Высокая7,5 | — | 6,5 % | 8 мар. 2005 г. |
32Наблюдать | CVE-2004-1307Эксплойта нет | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code vilibtiff · libtiff | Высокая7,5 | — | 6,3 % | 21 дек. 2004 г. |
32Наблюдать | CVE-2004-0827Эксплойта нет | Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a deimagemagick · imagemagick | Высокая7,5 | — | 5,5 % | 16 сент. 2004 г. |
31Наблюдать | CVE-2004-0817Эксплойта нет | Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.enlightenment · imlib | Высокая7,5 | — | 4,9 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2001-0440Proof of concept | Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitralicq · licq | Высокая7,5 | — | 4,6 % | 2 июл. 2001 г. |
31Наблюдать | CVE-2004-0801Эксплойта нет | Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitralinuxprinting.org · foomatic-filters | Высокая7,5 | — | 4,3 % | 16 сент. 2004 г. |
31Наблюдать | CVE-2005-0373Эксплойта нет | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | Высокая7,5 | — | 3,9 % | 7 окт. 2004 г. |
31Наблюдать | CVE-2005-0754Эксплойта нет | Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbikde · quanta | Высокая7,5 | — | 3,0 % | 22 апр. 2005 г. |
- CVE-2003-078060На этой неделе
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privil
КритическаяCVSS 9,0Proof of conceptEPSS 78 %mysql · mysql22 сент. 2003 г.
- CVE-2000-066648В плане
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote at
КритическаяCVSS 10,0Proof of conceptEPSS 26 %conectiva · linux16 июл. 2000 г.
- CVE-2004-055748В плане
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers t
КритическаяCVSS 10,0Proof of conceptEPSS 25 %sox · sox6 авг. 2004 г.
- CVE-2000-084445В плане
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke
КритическаяCVSS 10,0Proof of conceptEPSS 16 %caldera · openlinux ebuilder14 нояб. 2000 г.
- CVE-2004-088244В плане
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a
КритическаяCVSS 10,0Эксплойта нетEPSS 14 %samba · samba27 янв. 2005 г.
- CVE-2002-008343В плане
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
КритическаяCVSS 9,8Proof of conceptEPSS 15 %immunix · immunix15 мар. 2002 г.
- CVE-2004-090243В плане
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %mozilla · mozilla27 янв. 2005 г.
- CVE-2004-090343В плане
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %mozilla · mozilla27 янв. 2005 г.
- CVE-2004-102942В плане
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly rest
КритическаяCVSS 9,3Proof of conceptEPSS 17 %sun · jdk1 мар. 2005 г.
- CVE-2004-090442В плане
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %mozilla · firefox31 дек. 2004 г.
- CVE-2004-101242В плане
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %carnegie mellon university · cyrus imap server10 янв. 2005 г.
- CVE-2004-101142В плане
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %carnegie mellon university · cyrus imap server10 янв. 2005 г.
- CVE-2004-101342В плане
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %carnegie mellon university · cyrus imap server10 янв. 2005 г.
- CVE-2005-362541В плане
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %libextractor · libextractor31 дек. 2005 г.
- CVE-2000-074741В плане
The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %conectiva · linux20 окт. 2000 г.
- CVE-2001-069034Наблюдать
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %conectiva · linux20 сент. 2001 г.
- CVE-2001-013633Наблюдать
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman
СредняяCVSS 5,0Proof of conceptEPSS 45 %proftpd · proftpd12 мар. 2001 г.
- CVE-2005-069932Наблюдать
Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and ea
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %ethereal group · ethereal8 мар. 2005 г.
- CVE-2004-130732Наблюдать
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %libtiff · libtiff21 дек. 2004 г.
- CVE-2004-082732Наблюдать
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a de
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %imagemagick · imagemagick16 сент. 2004 г.
- CVE-2004-081731Наблюдать
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %enlightenment · imlib31 дек. 2004 г.
- CVE-2001-044031Наблюдать
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitra
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %licq · licq2 июл. 2001 г.
- CVE-2004-080131Наблюдать
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitra
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %linuxprinting.org · foomatic-filters16 сент. 2004 г.
- CVE-2005-037331Наблюдать
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %cyrus · sasl7 окт. 2004 г.
- CVE-2005-075431Наблюдать
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbi
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %kde · quanta22 апр. 2005 г.