Записи extensis
10 опубликованных записей вендора extensis.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2013-3944Эксплойта нет | Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via extensis · mrsid · CWE-787 | Высокая7,8 | — | 27,5 % | 2 янв. 2020 г. |
36Наблюдать | CVE-2022-24254Эксплойта нет | An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execextensis · portfolio · CWE-434 | Высокая8,8 | — | 2,6 % | 1 мар. 2022 г. |
36Наблюдать | CVE-2022-24252Эксплойта нет | An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to executeextensis · portfolio · CWE-434 | Высокая8,8 | — | 2,3 % | 1 мар. 2022 г. |
35Наблюдать | CVE-2022-24255Эксплойта нет | Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.extensis · portfolio · CWE-798 | Высокая8,8 | — | 1,4 % | 1 мар. 2022 г. |
35Наблюдать | CVE-2022-24251Эксплойта нет | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload functextensis · portfolio · CWE-434 | Высокая8,8 | — | 1,3 % | 1 мар. 2022 г. |
35Наблюдать | CVE-2022-24253Эксплойта нет | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransfeextensis · portfolio · CWE-434 | Высокая8,8 | — | 1,3 % | 1 мар. 2022 г. |
32Наблюдать | CVE-2013-3946Эксплойта нет | Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via aextensis · mrsid · CWE-787 | Высокая7,8 | — | 2,5 % | 2 янв. 2020 г. |
32Наблюдать | CVE-2013-3945Эксплойта нет | The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.extensis · mrsid · CWE-20 | Высокая7,8 | — | 2,1 % | 2 янв. 2020 г. |
24Наблюдать | CVE-2017-18006Эксплойта нет | netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.extensis · portfolio netpublish · CWE-79 | Средняя6,1 | — | 0,7 % | 31 дек. 2017 г. |
21Наблюдать | CVE-2005-4510Proof of concept | Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences inextensis · netpublish server | Средняя5,0 | — | 2,9 % | 22 дек. 2005 г. |
- CVE-2013-394439Наблюдать
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via
ВысокаяCVSS 7,8Эксплойта нетEPSS 28 %extensis · mrsid2 янв. 2020 г.
- CVE-2022-2425436Наблюдать
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to exec
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %extensis · portfolio1 мар. 2022 г.
- CVE-2022-2425236Наблюдать
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %extensis · portfolio1 мар. 2022 г.
- CVE-2022-2425535Наблюдать
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %extensis · portfolio1 мар. 2022 г.
- CVE-2022-2425135Наблюдать
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload funct
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %extensis · portfolio1 мар. 2022 г.
- CVE-2022-2425335Наблюдать
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransfe
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %extensis · portfolio1 мар. 2022 г.
- CVE-2013-394632Наблюдать
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %extensis · mrsid2 янв. 2020 г.
- CVE-2013-394532Наблюдать
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %extensis · mrsid2 янв. 2020 г.
- CVE-2017-1800624Наблюдать
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %extensis · portfolio netpublish31 дек. 2017 г.
- CVE-2005-451021Наблюдать
Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in
СредняяCVSS 5,0Proof of conceptEPSS 3 %extensis · netpublish server22 дек. 2005 г.