Записи dia
6 опубликованных записей вендора dia.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 83,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-134 Use of Externally-Controlled Format String2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2006-1550Эксплойта нет | Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to hadia · dia · CWE-119 | Высокая7,6 | — | 2,5 % | 30 мар. 2006 г. |
31Наблюдать | CVE-2006-2453Эксплойта нет | Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-200dia · dia · CWE-134 | Высокая7,5 | — | 2,2 % | 28 мая 2006 г. |
30Наблюдать | CVE-2007-3408Эксплойта нет | Multiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involving the use of vulnerdia · dia | Высокая7,5 | — | 1,2 % | 26 июн. 2007 г. |
27Наблюдать | CVE-2008-5984Эксплойта нет | Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrarydia · dia | Средняя6,9 | — | 0,4 % | 28 янв. 2009 г. |
22Наблюдать | CVE-2006-2480Proof of concept | Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary cdia · dia · CWE-134 | Средняя5,1 | — | 7,6 % | 19 мая 2006 г. |
21Наблюдать | CVE-2005-2966Эксплойта нет | The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a dia · dia | Средняя5,1 | — | 2,6 % | 5 окт. 2005 г. |
- CVE-2006-155031Наблюдать
Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to ha
ВысокаяCVSS 7,6Эксплойта нетEPSS 2 %dia · dia30 мар. 2006 г.
- CVE-2006-245331Наблюдать
Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-200
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dia · dia28 мая 2006 г.
- CVE-2007-340830Наблюдать
Multiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involving the use of vulner
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dia · dia26 июн. 2007 г.
- CVE-2008-598427Наблюдать
Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary
СредняяCVSS 6,9Эксплойта нетEPSS 0 %dia · dia28 янв. 2009 г.
- CVE-2006-248022Наблюдать
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary c
СредняяCVSS 5,1Proof of conceptEPSS 8 %dia · dia19 мая 2006 г.
- CVE-2005-296621Наблюдать
The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a
СредняяCVSS 5,1Эксплойта нетEPSS 3 %dia · dia5 окт. 2005 г.