Записи KeePass
8 опубликованных записей вендора keepass.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 25 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-319 Cleartext Transmission of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2023-32784Proof of concept | In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or nkeepass · keepass · CWE-319 | Высокая7,5 | — | 4,4 % | 15 мая 2023 г. |
31Наблюдать | CVE-2022-0725Proof of concept | A flaw was found in keepass.keepass · keepass · CWE-200 | Высокая7,5 | — | 2,5 % | 10 мар. 2022 г. |
31Наблюдать | CVE-2016-5119Эксплойта нет | The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the versiokeepass · keepass · CWE-20 | Высокая7,5 | — | 2,3 % | 23 янв. 2017 г. |
31Наблюдать | CVE-2019-20184Эксплойта нет | KeePass 2.4.1 allows CSV injection in the title field of a CSV export.keepass · keepass · CWE-1236 | Высокая7,8 | — | 1,6 % | 9 янв. 2020 г. |
30Наблюдать | CVE-2017-1000066Эксплойта нет | The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in thekeepass · keepass | Высокая7,5 | — | 1,4 % | 17 июл. 2017 г. |
27Наблюдать | CVE-2010-5196Эксплойта нет | Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dllkeepass · password safe | Средняя6,9 | — | 0,6 % | 6 сент. 2012 г. |
27Наблюдать | CVE-2010-5200Эксплойта нет | Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in thekeepass · keepass | Средняя6,9 | — | 0,4 % | 6 сент. 2012 г. |
23Наблюдать | CVE-2023-24055Proof of concept | KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the clearkeepass · keepass · CWE-312 | Средняя5,5 | — | 3,7 % | 22 янв. 2023 г. |
- CVE-2023-3278431Наблюдать
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or n
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %keepass · keepass15 мая 2023 г.
- CVE-2022-072531Наблюдать
A flaw was found in keepass.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %keepass · keepass10 мар. 2022 г.
- CVE-2016-511931Наблюдать
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the versio
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %keepass · keepass23 янв. 2017 г.
- CVE-2019-2018431Наблюдать
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %keepass · keepass9 янв. 2020 г.
- CVE-2017-100006630Наблюдать
The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keepass · keepass17 июл. 2017 г.
- CVE-2010-519627Наблюдать
Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll
СредняяCVSS 6,9Эксплойта нетEPSS 1 %keepass · password safe6 сент. 2012 г.
- CVE-2010-520027Наблюдать
Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the
СредняяCVSS 6,9Эксплойта нетEPSS 0 %keepass · keepass6 сент. 2012 г.
- CVE-2023-2405523Наблюдать
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the clear
СредняяCVSS 5,5Proof of conceptEPSS 4 %keepass · keepass22 янв. 2023 г.