Записи intercom
8 опубликованных записей вендора intercom.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication2
- CWE-295 Improper Certificate Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-10817Эксплойта нет | MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.intercom · malion · CWE-287 | Критическая9,8 | — | 3,1 % | 4 авг. 2017 г. |
40В плане | CVE-2017-10816Эксплойта нет | SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Rintercom · malion · CWE-89 | Критическая9,8 | — | 2,2 % | 4 авг. 2017 г. |
40В плане | CVE-2017-10818Эксплойта нет | MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection seintercom · malion · CWE-798 | Критическая9,8 | — | 1,8 % | 4 авг. 2017 г. |
33Наблюдать | CVE-2017-10815Эксплойта нет | MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control"intercom · malion · CWE-287 | Высокая8,1 | — | 2,3 % | 4 авг. 2017 г. |
31Наблюдать | CVE-2019-14365Эксплойта нет | The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.intercom · intercom · CWE-200 | Высокая7,5 | — | 1,9 % | 12 нояб. 2019 г. |
27Наблюдать | CVE-2014-3881Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authenticintercom · web kyukincho · CWE-352 | Средняя6,8 | — | 0,6 % | 27 июн. 2014 г. |
23Наблюдать | CVE-2017-10819Эксплойта нет | MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communicatiointercom · malion · CWE-295 | Средняя5,9 | — | 0,8 % | 4 авг. 2017 г. |
17Наблюдать | CVE-2014-2006Эксплойта нет | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web scriptintercom · web kyukincho · CWE-79 | Средняя4,3 | — | 1,1 % | 27 июн. 2014 г. |
- CVE-2017-1081740В плане
MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %intercom · malion4 авг. 2017 г.
- CVE-2017-1081640В плане
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via R
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intercom · malion4 авг. 2017 г.
- CVE-2017-1081840В плане
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection se
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intercom · malion4 авг. 2017 г.
- CVE-2017-1081533Наблюдать
MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control"
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %intercom · malion4 авг. 2017 г.
- CVE-2019-1436531Наблюдать
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %intercom · intercom12 нояб. 2019 г.
- CVE-2014-388127Наблюдать
Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentic
СредняяCVSS 6,8Эксплойта нетEPSS 1 %intercom · web kyukincho27 июн. 2014 г.
- CVE-2017-1081923Наблюдать
MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communicatio
СредняяCVSS 5,9Эксплойта нетEPSS 1 %intercom · malion4 авг. 2017 г.
- CVE-2014-200617Наблюдать
Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 1 %intercom · web kyukincho27 июн. 2014 г.