Записи NIH
8 опубликованных записей вендора nih.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 37,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-189 Numeric Errors2
- CWE-416 Use After Free2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-787 Out-of-bounds Write1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2018-16716Proof of concept | A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in readnih · ncbi toolbox · CWE-22 | Критическая9,1 | — | 8,6 % | 2 мая 2019 г. |
39Наблюдать | CVE-2018-16717Эксплойта нет | A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.nih · ncbi toolbox · CWE-787 | Критическая9,8 | — | 1,6 % | 2 мая 2019 г. |
39Наблюдать | CVE-2024-24794Эксплойта нет | A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5.nih · libdicom · CWE-416 | Критическая9,8 | — | 1,1 % | 20 февр. 2024 г. |
39Наблюдать | CVE-2024-24793Эксплойта нет | A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5.nih · libdicom · CWE-416 | Критическая9,8 | — | 1,1 % | 20 февр. 2024 г. |
38Наблюдать | CVE-2015-2331Эксплойта нет | Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.php · php · CWE-189 | Высокая7,5 | — | 27,7 % | 30 мар. 2015 г. |
31Наблюдать | CVE-2012-1162Эксплойта нет | Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (nih · libzip · CWE-119 | Высокая7,5 | — | 4,0 % | 12 июл. 2012 г. |
28Наблюдать | CVE-2012-1163Эксплойта нет | Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size anih · libzip · CWE-189 | Средняя6,8 | — | 2,6 % | 12 июл. 2012 г. |
24Наблюдать | CVE-2018-16718Эксплойта нет | An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.nih · ncbi toolbox · CWE-79 | Средняя6,1 | — | 0,8 % | 2 мая 2019 г. |
- CVE-2018-1671639Наблюдать
A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in read
КритическаяCVSS 9,1Proof of conceptEPSS 9 %nih · ncbi toolbox2 мая 2019 г.
- CVE-2018-1671739Наблюдать
A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nih · ncbi toolbox2 мая 2019 г.
- CVE-2024-2479439Наблюдать
A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nih · libdicom20 февр. 2024 г.
- CVE-2024-2479339Наблюдать
A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nih · libdicom20 февр. 2024 г.
- CVE-2015-233138Наблюдать
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 28 %php · php30 мар. 2015 г.
- CVE-2012-116231Наблюдать
Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %nih · libzip12 июл. 2012 г.
- CVE-2012-116328Наблюдать
Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size a
СредняяCVSS 6,8Эксплойта нетEPSS 3 %nih · libzip12 июл. 2012 г.
- CVE-2018-1671824Наблюдать
An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nih · ncbi toolbox2 мая 2019 г.