Записи mageia
22 опубликованных записей вендора mageia.
Профиль для исследователя
- Попали в KEV
- 2 · 9,1 %
- С эксплойтом
- 3 · 13,6 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 95,5 %
- Медиана: публикация → KEV
- 2683 дн.
Повторяющиеся классы
- CWE-399 Resource Management Errors5
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
43В плане | CVE-2014-3566Готовый эксплойт | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Низкая3,4 | — | 100,0 % | 14 окт. 2014 г. |
32Наблюдать | CVE-2014-9087Эксплойта нет | Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of segnupg · libksba · CWE-191 | Высокая7,5 | — | 5,7 % | 1 дек. 2014 г. |
31Наблюдать | CVE-2013-4159Эксплойта нет | ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fiopensuse · opensuse · CWE-264 | Высокая7,5 | — | 2,4 % | 6 авг. 2014 г. |
28Наблюдать | CVE-2014-3429Эксплойта нет | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute aripython · ipython notebook · CWE-94 | Средняя6,8 | — | 4,7 % | 7 авг. 2014 г. |
28Наблюдать | CVE-2014-8104Эксплойта нет | OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service openvpn · openvpn · CWE-399 | Средняя6,8 | — | 3,5 % | 3 дек. 2014 г. |
24Наблюдать | CVE-2014-5461Эксплойта нет | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial lua · lua · CWE-119 | Средняя5,0 | — | 11,7 % | 4 сент. 2014 г. |
23Наблюдать | CVE-2014-9116Эксплойта нет | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote amutt · mutt · CWE-119 | Средняя5,0 | — | 9,7 % | 2 дек. 2014 г. |
23Наблюдать | CVE-2014-9637Эксплойта нет | GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted dgnu · patch · CWE-399 | Средняя5,5 | — | 2,4 % | 25 авг. 2017 г. |
22Наблюдать | CVE-2014-8117Эксплойта нет | softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumptifile project · file · CWE-399 | Средняя5,0 | — | 5,9 % | 17 дек. 2014 г. |
21Наблюдать | CVE-2015-2189Эксплойта нет | Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x befwireshark · wireshark · CWE-189 | Средняя5,0 | — | 4,6 % | 7 мар. 2015 г. |
21Наблюдать | CVE-2014-8116Эксплойта нет | The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large nfile project · file · CWE-399 | Средняя5,0 | — | 4,4 % | 17 дек. 2014 г. |
21Наблюдать | CVE-2015-2188Эксплойта нет | epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize awireshark · wireshark · CWE-19 | Средняя5,0 | — | 4,4 % | 7 мар. 2015 г. |
21Наблюдать | CVE-2014-7204Эксплойта нет | jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cracanonical · ubuntu linux · CWE-399 | Средняя5,0 | — | 4,3 % | 7 окт. 2014 г. |
21Наблюдать | CVE-2015-2191Эксплойта нет | Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and wireshark · wireshark · CWE-189 | Средняя5,0 | — | 3,9 % | 7 мар. 2015 г. |
21Наблюдать | CVE-2014-1829Эксплойта нет | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirepython · requests · CWE-200 | Средняя5,0 | — | 2,2 % | 15 окт. 2014 г. |
18Наблюдать | CVE-2014-9253Эксплойта нет | The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers dokuwiki · dokuwiki · CWE-79 | Средняя4,3 | — | 2,4 % | 17 дек. 2014 г. |
15Наблюдать | CVE-2015-0236Эксплойта нет | libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)mageia · mageia · CWE-200 | Низкая3,5 | — | 1,8 % | 29 янв. 2015 г. |
13Наблюдать | CVE-2014-2524Эксплойта нет | The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlinkgnu · readline · CWE-59 | Низкая3,3 | — | 0,4 % | 20 авг. 2014 г. |
8Наблюдать | CVE-2014-3532Эксплойта нет | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service linux · linux kernel · CWE-20 | Низкая2,1 | — | 0,4 % | 19 июл. 2014 г. |
8Наблюдать | CVE-2014-8136Эксплойта нет | The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when amageia · mageia · CWE-264 | Низкая2,1 | — | 0,4 % | 19 дек. 2014 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-356643В плане
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
НизкаяCVSS 3,4Готовый эксплойтEPSS 100 %openssl · openssl14 окт. 2014 г.
- CVE-2014-908732Наблюдать
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of se
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %gnupg · libksba1 дек. 2014 г.
- CVE-2013-415931Наблюдать
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opensuse · opensuse6 авг. 2014 г.
- CVE-2014-342928Наблюдать
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute ar
СредняяCVSS 6,8Эксплойта нетEPSS 5 %ipython · ipython notebook7 авг. 2014 г.
- CVE-2014-810428Наблюдать
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service
СредняяCVSS 6,8Эксплойта нетEPSS 3 %openvpn · openvpn3 дек. 2014 г.
- CVE-2014-546124Наблюдать
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
СредняяCVSS 5,0Эксплойта нетEPSS 12 %lua · lua4 сент. 2014 г.
- CVE-2014-911623Наблюдать
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote a
СредняяCVSS 5,0Эксплойта нетEPSS 10 %mutt · mutt2 дек. 2014 г.
- CVE-2014-963723Наблюдать
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted d
СредняяCVSS 5,5Эксплойта нетEPSS 2 %gnu · patch25 авг. 2017 г.
- CVE-2014-811722Наблюдать
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumpti
СредняяCVSS 5,0Эксплойта нетEPSS 6 %file project · file17 дек. 2014 г.
- CVE-2015-218921Наблюдать
Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x bef
СредняяCVSS 5,0Эксплойта нетEPSS 5 %wireshark · wireshark7 мар. 2015 г.
- CVE-2014-811621Наблюдать
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large n
СредняяCVSS 5,0Эксплойта нетEPSS 4 %file project · file17 дек. 2014 г.
- CVE-2015-218821Наблюдать
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a
СредняяCVSS 5,0Эксплойта нетEPSS 4 %wireshark · wireshark7 мар. 2015 г.
- CVE-2014-720421Наблюдать
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cra
СредняяCVSS 5,0Эксплойта нетEPSS 4 %canonical · ubuntu linux7 окт. 2014 г.
- CVE-2015-219121Наблюдать
Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and
СредняяCVSS 5,0Эксплойта нетEPSS 4 %wireshark · wireshark7 мар. 2015 г.
- CVE-2014-182921Наблюдать
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redire
СредняяCVSS 5,0Эксплойта нетEPSS 2 %python · requests15 окт. 2014 г.
- CVE-2014-925318Наблюдать
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers
СредняяCVSS 4,3Эксплойта нетEPSS 2 %dokuwiki · dokuwiki17 дек. 2014 г.
- CVE-2015-023615Наблюдать
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)
НизкаяCVSS 3,5Эксплойта нетEPSS 2 %mageia · mageia29 янв. 2015 г.
- CVE-2014-252413Наблюдать
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %gnu · readline20 авг. 2014 г.
- CVE-2014-35328Наблюдать
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %linux · linux kernel19 июл. 2014 г.
- CVE-2014-81368Наблюдать
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when a
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %mageia · mageia19 дек. 2014 г.