Записи cvs
18 опубликованных записей вендора cvs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 83,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-415 Double Free1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2004-0396Proof of concept | Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers tocvs · cvs | Высокая7,5 | — | 67,5 % | 14 июн. 2004 г. |
44В плане | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Критическая10,0 | — | 13,2 % | 6 авг. 2004 г. |
43В плане | CVE-2012-0804Эксплойта нет | Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a decvs · cvs · CWE-119 | Критическая10,0 | — | 8,5 % | 29 мая 2012 г. |
42В плане | CVE-2004-0418Эксплойта нет | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Критическая10,0 | — | 5,7 % | 6 авг. 2004 г. |
41В плане | CVE-2004-0414Эксплойта нет | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator frcvs · cvs | Критическая10,0 | — | 4,0 % | 6 авг. 2004 г. |
37Наблюдать | CVE-2003-0015Proof of concept | Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary codecvs · cvs · CWE-415 | Высокая7,5 | — | 23,9 % | 7 февр. 2003 г. |
31Наблюдать | CVE-2005-0753Эксплойта нет | Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.cvs · cvs | Высокая7,5 | — | 4,7 % | 18 апр. 2005 г. |
31Наблюдать | CVE-2003-0977Эксплойта нет | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via cvs · cvs | Высокая7,5 | — | 2,3 % | 5 янв. 2004 г. |
31Наблюдать | CVE-2004-1342Эксплойта нет | CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acccvs · cvs | Высокая7,5 | — | 2,3 % | 27 апр. 2005 г. |
30Наблюдать | CVE-2004-1471Proof of concept | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commicvs · cvs | Высокая7,1 | — | 7,7 % | 31 дек. 2004 г. |
28Наблюдать | CVE-2000-0680Proof of concept | The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVScvs · cvs | Высокая7,2 | — | 1,3 % | 20 окт. 2000 г. |
21Наблюдать | CVE-2004-0417Эксплойта нет | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may cvs · cvs | Средняя5,0 | — | 3,1 % | 6 авг. 2004 г. |
21Наблюдать | CVE-2004-0405Эксплойта нет | CVS before 1.11 allows CVS clients to read arbitrary files via ..cvs · cvs | Средняя5,0 | — | 2,4 % | 1 июн. 2004 г. |
21Наблюдать | CVE-2004-1343Эксплойта нет | CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouicvs · cvs | Средняя5,0 | — | 1,9 % | 31 дек. 2004 г. |
21Наблюдать | CVE-2002-0092Эксплойта нет | CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) cvs · cvs | Средняя5,0 | — | 1,8 % | 15 мар. 2002 г. |
18Наблюдать | CVE-2005-2693Эксплойта нет | cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbicvs · cvs | Средняя4,6 | — | 0,4 % | 26 авг. 2005 г. |
11Наблюдать | CVE-2004-0180Эксплойта нет | The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolutecvs · cvs | Низкая2,6 | — | 1,8 % | 1 июн. 2004 г. |
8Наблюдать | CVE-2000-0679Proof of concept | The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary cvs · cvs | Низкая2,1 | — | 0,7 % | 20 окт. 2000 г. |
- CVE-2004-039650В плане
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 68 %cvs · cvs14 июн. 2004 г.
- CVE-2004-041644В плане
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
КритическаяCVSS 10,0Proof of conceptEPSS 13 %cvs · cvs6 авг. 2004 г.
- CVE-2012-080443В плане
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a de
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %cvs · cvs29 мая 2012 г.
- CVE-2004-041842В плане
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %cvs · cvs6 авг. 2004 г.
- CVE-2004-041441В плане
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %cvs · cvs6 авг. 2004 г.
- CVE-2003-001537Наблюдать
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %cvs · cvs7 февр. 2003 г.
- CVE-2005-075331Наблюдать
Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %cvs · cvs18 апр. 2005 г.
- CVE-2003-097731Наблюдать
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cvs · cvs5 янв. 2004 г.
- CVE-2004-134231Наблюдать
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acc
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cvs · cvs27 апр. 2005 г.
- CVE-2004-147130Наблюдать
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi
ВысокаяCVSS 7,1Proof of conceptEPSS 8 %cvs · cvs31 дек. 2004 г.
- CVE-2000-068028Наблюдать
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %cvs · cvs20 окт. 2000 г.
- CVE-2004-041721Наблюдать
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may
СредняяCVSS 5,0Эксплойта нетEPSS 3 %cvs · cvs6 авг. 2004 г.
- CVE-2004-040521Наблюдать
CVS before 1.11 allows CVS clients to read arbitrary files via ..
СредняяCVSS 5,0Эксплойта нетEPSS 2 %cvs · cvs1 июн. 2004 г.
- CVE-2004-134321Наблюдать
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repoui
СредняяCVSS 5,0Эксплойта нетEPSS 2 %cvs · cvs31 дек. 2004 г.
- CVE-2002-009221Наблюдать
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash)
СредняяCVSS 5,0Эксплойта нетEPSS 2 %cvs · cvs15 мар. 2002 г.
- CVE-2005-269318Наблюдать
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbi
СредняяCVSS 4,6Эксплойта нетEPSS 0 %cvs · cvs26 авг. 2005 г.
- CVE-2004-018011Наблюдать
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %cvs · cvs1 июн. 2004 г.
- CVE-2000-06798Наблюдать
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary
НизкаяCVSS 2,1Proof of conceptEPSS 1 %cvs · cvs20 окт. 2000 г.