Записи keybase
8 опубликованных записей вендора keybase.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-426 Untrusted Search Path1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-7249Эксплойта нет | In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one usekeybase · keybase · CWE-367 | Критическая9,8 | — | 2,5 % | 31 янв. 2019 г. |
36Наблюдать | CVE-2021-34422Эксплойта нет | Path traversal of file names in Keybase Client for Windowskeybase · keybase · CWE-22 | Критическая9,0 | — | 1,4 % | 11 нояб. 2021 г. |
31Наблюдать | CVE-2018-18629Proof of concept | An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux.keybase · keybase · CWE-426 | Высокая7,8 | — | 1,5 % | 20 дек. 2018 г. |
31Наблюдать | CVE-2021-34426Эксплойта нет | Arbitrary command execution in Keybase Client for Windowskeybase · keybase | Высокая7,8 | — | 0,2 % | 14 дек. 2021 г. |
30Наблюдать | CVE-2019-16992Эксплойта нет | The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocukeybase · keybase · CWE-347 | Высокая7,5 | — | 0,9 % | 29 сент. 2019 г. |
22Наблюдать | CVE-2021-23827Эксплойта нет | Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive medikeybase · keybase · CWE-312 | Средняя5,5 | — | 0,3 % | 22 февр. 2021 г. |
17Наблюдать | CVE-2021-34421Эксплойта нет | Retained exploded messages in Keybase Clients for Android and iOSkeybase · keybase · CWE-459 | Средняя4,3 | — | 0,7 % | 11 нояб. 2021 г. |
14Наблюдать | CVE-2022-22779Эксплойта нет | Retained exploded messages in Keybase clients for macOS and Windowskeybase · keybase · CWE-212 | Низкая3,7 | — | 0,8 % | 9 февр. 2022 г. |
- CVE-2019-724940В плане
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one use
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %keybase · keybase31 янв. 2019 г.
- CVE-2021-3442236Наблюдать
Path traversal of file names in Keybase Client for Windows
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %keybase · keybase11 нояб. 2021 г.
- CVE-2018-1862931Наблюдать
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux.
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %keybase · keybase20 дек. 2018 г.
- CVE-2021-3442631Наблюдать
Arbitrary command execution in Keybase Client for Windows
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %keybase · keybase14 дек. 2021 г.
- CVE-2019-1699230Наблюдать
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocu
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keybase · keybase29 сент. 2019 г.
- CVE-2021-2382722Наблюдать
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive medi
СредняяCVSS 5,5Эксплойта нетEPSS 0 %keybase · keybase22 февр. 2021 г.
- CVE-2021-3442117Наблюдать
Retained exploded messages in Keybase Clients for Android and iOS
СредняяCVSS 4,3Эксплойта нетEPSS 1 %keybase · keybase11 нояб. 2021 г.
- CVE-2022-2277914Наблюдать
Retained exploded messages in Keybase clients for macOS and Windows
НизкаяCVSS 3,7Эксплойта нетEPSS 1 %keybase · keybase9 февр. 2022 г.