Записи openpkg
27 опубликованных записей вендора openpkg.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,7 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 88,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-131 Incorrect Calculation of Buffer Size1
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-203 Observable Discrepancy1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2004-0990Proof of concept | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of sergd graphics library · gdlib | Критическая10,0 | — | 28,3 % | 1 мар. 2005 г. |
47В плане | CVE-2004-0333Proof of concept | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Критическая10,0 | — | 24,2 % | 23 нояб. 2004 г. |
44В плане | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Критическая10,0 | — | 13,2 % | 6 авг. 2004 г. |
43В плане | CVE-2003-0190Готовый эксплойт | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, whichopenbsd · openssh · CWE-203 | Средняя5,0 | — | 76,8 % | 12 мая 2003 г. |
43В плане | CVE-2002-0083Proof of concept | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Критическая9,8 | — | 14,7 % | 15 мар. 2002 г. |
43В плане | CVE-2004-1065Эксплойта нет | Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary codphp · php | Критическая10,0 | — | 10,0 % | 10 янв. 2005 г. |
42В плане | CVE-2004-1019Эксплойта нет | The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitphp · php · CWE-20 | Критическая10,0 | — | 8,0 % | 10 янв. 2005 г. |
42В плане | CVE-2004-1012Эксплойта нет | The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Критическая10,0 | — | 6,0 % | 10 янв. 2005 г. |
42В плане | CVE-2004-0413Эксплойта нет | libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allowsubversion · subversion | Критическая10,0 | — | 5,9 % | 6 авг. 2004 г. |
42В плане | CVE-2004-1011Эксплойта нет | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execcarnegie mellon university · cyrus imap server | Критическая10,0 | — | 5,8 % | 10 янв. 2005 г. |
42В плане | CVE-2004-1013Эксплойта нет | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Критическая10,0 | — | 5,8 % | 10 янв. 2005 г. |
42В плане | CVE-2004-0418Эксплойта нет | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Критическая10,0 | — | 5,7 % | 6 авг. 2004 г. |
41В плане | CVE-2004-0772Эксплойта нет | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Критическая9,8 | — | 7,0 % | 20 окт. 2004 г. |
41В плане | CVE-2004-0414Эксплойта нет | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator frcvs · cvs | Критическая10,0 | — | 4,0 % | 6 авг. 2004 г. |
36Наблюдать | CVE-2004-0594Proof of concept | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enahp · hp-ux · CWE-367 | Средняя5,1 | — | 54,9 % | 27 июл. 2004 г. |
32Наблюдать | CVE-2004-0940Proof of concept | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to executeapache · http server · CWE-131 | Высокая7,8 | — | 4,8 % | 9 февр. 2005 г. |
31Наблюдать | CVE-2007-5116Эксплойта нет | Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackerdebian · debian linux · CWE-119 | Высокая7,5 | — | 4,8 % | 7 нояб. 2007 г. |
31Наблюдать | CVE-2005-0373Эксплойта нет | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | Высокая7,5 | — | 3,9 % | 7 окт. 2004 г. |
31Наблюдать | CVE-2002-0985Эксплойта нет | Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify cphp · php · CWE-88 | Высокая7,5 | — | 3,0 % | 24 сент. 2002 г. |
30Наблюдать | CVE-2004-1471Proof of concept | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commicvs · cvs | Высокая7,1 | — | 7,7 % | 31 дек. 2004 г. |
28Наблюдать | CVE-2004-0957Эксплойта нет | Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), openpkg · openpkg | Средняя6,8 | — | 2,4 % | 9 февр. 2005 г. |
25Наблюдать | CVE-2004-0918Эксплойта нет | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a desquid · squid · CWE-399 | Средняя5,0 | — | 15,8 % | 27 янв. 2005 г. |
22Наблюдать | CVE-2003-0147Эксплойта нет | OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factopenssl · openssl | Средняя5,0 | — | 6,4 % | 31 мар. 2003 г. |
21Наблюдать | CVE-2004-0421Эксплойта нет | The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG libpng · libpng · CWE-125 | Средняя5,0 | — | 4,1 % | 18 авг. 2004 г. |
21Наблюдать | CVE-2004-0417Эксплойта нет | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may cvs · cvs | Средняя5,0 | — | 3,1 % | 6 авг. 2004 г. |
- CVE-2004-099048В плане
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of ser
КритическаяCVSS 10,0Proof of conceptEPSS 28 %gd graphics library · gdlib1 мар. 2005 г.
- CVE-2004-033347В плане
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
КритическаяCVSS 10,0Proof of conceptEPSS 24 %uudeview · uudeview23 нояб. 2004 г.
- CVE-2004-041644В плане
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
КритическаяCVSS 10,0Proof of conceptEPSS 13 %cvs · cvs6 авг. 2004 г.
- CVE-2003-019043В плане
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which
СредняяCVSS 5,0Готовый эксплойтEPSS 77 %openbsd · openssh12 мая 2003 г.
- CVE-2002-008343В плане
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
КритическаяCVSS 9,8Proof of conceptEPSS 15 %immunix · immunix15 мар. 2002 г.
- CVE-2004-106543В плане
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary cod
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %php · php10 янв. 2005 г.
- CVE-2004-101942В плане
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbit
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %php · php10 янв. 2005 г.
- CVE-2004-101242В плане
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %carnegie mellon university · cyrus imap server10 янв. 2005 г.
- CVE-2004-041342В плане
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allow
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %subversion · subversion6 авг. 2004 г.
- CVE-2004-101142В плане
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %carnegie mellon university · cyrus imap server10 янв. 2005 г.
- CVE-2004-101342В плане
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %carnegie mellon university · cyrus imap server10 янв. 2005 г.
- CVE-2004-041842В плане
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %cvs · cvs6 авг. 2004 г.
- CVE-2004-077241В плане
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %mit · kerberos 520 окт. 2004 г.
- CVE-2004-041441В плане
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %cvs · cvs6 авг. 2004 г.
- CVE-2004-059436Наблюдать
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is ena
СредняяCVSS 5,1Proof of conceptEPSS 55 %hp · hp-ux27 июл. 2004 г.
- CVE-2004-094032Наблюдать
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %apache · http server9 февр. 2005 г.
- CVE-2007-511631Наблюдать
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %debian · debian linux7 нояб. 2007 г.
- CVE-2005-037331Наблюдать
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %cyrus · sasl7 окт. 2004 г.
- CVE-2002-098531Наблюдать
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify c
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %php · php24 сент. 2002 г.
- CVE-2004-147130Наблюдать
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi
ВысокаяCVSS 7,1Proof of conceptEPSS 8 %cvs · cvs31 дек. 2004 г.
- CVE-2004-095728Наблюдать
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore),
СредняяCVSS 6,8Эксплойта нетEPSS 2 %openpkg · openpkg9 февр. 2005 г.
- CVE-2004-091825Наблюдать
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de
СредняяCVSS 5,0Эксплойта нетEPSS 16 %squid · squid27 янв. 2005 г.
- CVE-2003-014722Наблюдать
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining fact
СредняяCVSS 5,0Эксплойта нетEPSS 6 %openssl · openssl31 мар. 2003 г.
- CVE-2004-042121Наблюдать
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG
СредняяCVSS 5,0Эксплойта нетEPSS 4 %libpng · libpng18 авг. 2004 г.
- CVE-2004-041721Наблюдать
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may
СредняяCVSS 5,0Эксплойта нетEPSS 3 %cvs · cvs6 авг. 2004 г.