Записи datev
4 опубликованных записей вендора datev.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-426 Untrusted Search Path1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2010-0689Эксплойта нет | The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allodatev · base system | Критическая10,0 | — | 6,0 % | 26 февр. 2010 г. |
38Наблюдать | CVE-2011-5158Эксплойта нет | Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 adatev · grundpaket basis · CWE-426 | Критическая9,3 | — | 2,0 % | 7 сент. 2012 г. |
24Наблюдать | CVE-2023-33387Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allowdatev · eg personal-management system comfort\/comfort plus · CWE-79 | Средняя6,1 | — | 0,5 % | 22 июн. 2023 г. |
18Наблюдать | CVE-2003-1169Proof of concept | DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access resdatev · nutzungskontrolle | Средняя4,6 | — | 0,8 % | 31 дек. 2003 г. |
- CVE-2010-068942В плане
The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allo
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %datev · base system26 февр. 2010 г.
- CVE-2011-515838Наблюдать
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 a
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %datev · grundpaket basis7 сент. 2012 г.
- CVE-2023-3338724Наблюдать
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allow
СредняяCVSS 6,1Эксплойта нетEPSS 1 %datev · eg personal-management system comfort\/comfort plus22 июн. 2023 г.
- CVE-2003-116918Наблюдать
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access res
СредняяCVSS 4,6Proof of conceptEPSS 1 %datev · nutzungskontrolle31 дек. 2003 г.