Записи feep
6 опубликованных записей вендора feep.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read2
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-189 Numeric Errors1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-33643Эксплойта нет | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable feep · libtar · CWE-125 | Критическая9,1 | — | 1,7 % | 10 авг. 2022 г. |
32Наблюдать | CVE-2021-33644Эксплойта нет | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable feep · libtar · CWE-125 | Высокая8,1 | — | 1,4 % | 10 авг. 2022 г. |
31Наблюдать | CVE-2021-33645Эксплойта нет | The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.feep · libtar · CWE-401 | Высокая7,5 | — | 1,8 % | 10 авг. 2022 г. |
31Наблюдать | CVE-2021-33646Эксплойта нет | The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.feep · libtar · CWE-401 | Высокая7,5 | — | 1,8 % | 10 авг. 2022 г. |
29Наблюдать | CVE-2013-4397Эксплойта нет | Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of servicredhat · enterprise linux · CWE-189 | Средняя6,8 | — | 5,5 % | 17 окт. 2013 г. |
24Наблюдать | CVE-2013-4420Эксплойта нет | Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allofeep · libtar · CWE-22 | Средняя5,8 | — | 3,3 % | 20 февр. 2014 г. |
- CVE-2021-3364336Наблюдать
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %feep · libtar10 авг. 2022 г.
- CVE-2021-3364432Наблюдать
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %feep · libtar10 авг. 2022 г.
- CVE-2021-3364531Наблюдать
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %feep · libtar10 авг. 2022 г.
- CVE-2021-3364631Наблюдать
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %feep · libtar10 авг. 2022 г.
- CVE-2013-439729Наблюдать
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of servic
СредняяCVSS 6,8Эксплойта нетEPSS 5 %redhat · enterprise linux17 окт. 2013 г.
- CVE-2013-442024Наблюдать
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allo
СредняяCVSS 5,8Эксплойта нетEPSS 3 %feep · libtar20 февр. 2014 г.