Записи getbootstrap
9 опубликованных записей вендора getbootstrap.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-10842Эксплойта нет | Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org.getbootstrap · bootstrap-sass · CWE-94 | Критическая9,8 | — | 4,9 % | 4 апр. 2019 г. |
29Наблюдать | CVE-2019-8331Proof of concept | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.getbootstrap · bootstrap · CWE-79 | Средняя6,1 | — | 16,4 % | 20 февр. 2019 г. |
25Наблюдать | CVE-2018-14041Proof of concept | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.getbootstrap · bootstrap · CWE-79 | Средняя6,1 | — | 4,3 % | 13 июл. 2018 г. |
25Наблюдать | CVE-2018-14040Proof of concept | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.debian · debian linux · CWE-79 | Средняя6,1 | — | 4,1 % | 13 июл. 2018 г. |
25Наблюдать | CVE-2016-10735Proof of concept | In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability thangetbootstrap · bootstrap · CWE-79 | Средняя6,1 | — | 4,0 % | 9 янв. 2019 г. |
25Наблюдать | CVE-2018-14042Proof of concept | In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.getbootstrap · bootstrap · CWE-79 | Средняя6,1 | — | 4,0 % | 13 июл. 2018 г. |
25Наблюдать | CVE-2018-20677Эксплойта нет | In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.getbootstrap · bootstrap · CWE-79 | Средняя6,1 | — | 4,0 % | 9 янв. 2019 г. |
25Наблюдать | CVE-2018-20676Эксплойта нет | In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.getbootstrap · bootstrap · CWE-79 | Средняя6,1 | — | 3,8 % | 9 янв. 2019 г. |
25Наблюдать | CVE-2024-6485Proof of concept | XSS in Bootstrap button componentbootstrap · bootstrap · CWE-79 | Средняя6,4 | — | 0,5 % | 11 июл. 2024 г. |
- CVE-2019-1084240В плане
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %getbootstrap · bootstrap-sass4 апр. 2019 г.
- CVE-2019-833129Наблюдать
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
СредняяCVSS 6,1Proof of conceptEPSS 16 %getbootstrap · bootstrap20 февр. 2019 г.
- CVE-2018-1404125Наблюдать
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
СредняяCVSS 6,1Proof of conceptEPSS 4 %getbootstrap · bootstrap13 июл. 2018 г.
- CVE-2018-1404025Наблюдать
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
СредняяCVSS 6,1Proof of conceptEPSS 4 %debian · debian linux13 июл. 2018 г.
- CVE-2016-1073525Наблюдать
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than
СредняяCVSS 6,1Proof of conceptEPSS 4 %getbootstrap · bootstrap9 янв. 2019 г.
- CVE-2018-1404225Наблюдать
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
СредняяCVSS 6,1Proof of conceptEPSS 4 %getbootstrap · bootstrap13 июл. 2018 г.
- CVE-2018-2067725Наблюдать
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
СредняяCVSS 6,1Эксплойта нетEPSS 4 %getbootstrap · bootstrap9 янв. 2019 г.
- CVE-2018-2067625Наблюдать
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
СредняяCVSS 6,1Эксплойта нетEPSS 4 %getbootstrap · bootstrap9 янв. 2019 г.
- CVE-2024-648525Наблюдать
XSS in Bootstrap button component
СредняяCVSS 6,4Proof of conceptEPSS 0 %bootstrap · bootstrap11 июл. 2024 г.