Записи pgp
23 опубликованных записей вендора pgp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 4,3 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-459 Incomplete Cleanup2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2001-1320Готовый эксплойт | Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via expgp · keyserver | Высокая7,5 | — | 68,3 % | 16 июл. 2001 г. |
41В плане | CVE-2001-1252Эксплойта нет | Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs tpgp · keyserver | Критическая10,0 | — | 3,2 % | 28 сент. 2001 г. |
38Наблюдать | CVE-2010-3397Эксплойта нет | Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local userpgp · desktop | Критическая9,3 | — | 4,2 % | 15 сент. 2010 г. |
32Наблюдать | CVE-2001-1456Эксплойта нет | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitramcafee · webshield smtp · CWE-119 | Высокая7,5 | — | 5,7 % | 4 сент. 2001 г. |
31Наблюдать | CVE-2002-0850Эксплойта нет | Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long fpgp · corporate desktop | Высокая7,5 | — | 3,2 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2002-0685Эксплойта нет | Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0pgp · desktop security | Высокая7,5 | — | 2,6 % | 23 июл. 2002 г. |
31Наблюдать | CVE-2002-2069Эксплойта нет | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recpgp · personal privacy · CWE-459 | Высокая7,5 | — | 2,1 % | 31 дек. 2002 г. |
30Наблюдать | CVE-2007-0603Эксплойта нет | PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpspgp · corporate desktop | Высокая7,1 | — | 5,2 % | 30 янв. 2007 г. |
30Наблюдать | CVE-2001-1016Эксплойта нет | PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly pgp · corporate desktop | Высокая7,5 | — | 1,4 % | 4 сент. 2001 г. |
28Наблюдать | CVE-2009-0681Эксплойта нет | PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) causpgp · desktop · CWE-20 | Высокая7,2 | — | 0,4 % | 15 апр. 2009 г. |
22Наблюдать | CVE-2002-0788Эксплойта нет | An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartextpgp · corporate desktop · CWE-459 | Средняя5,5 | — | 0,4 % | 12 авг. 2002 г. |
22Наблюдать | CVE-2002-1696Эксплойта нет | Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically depgp · personal privacy · CWE-312 | Средняя5,5 | — | 0,3 % | 31 дек. 2002 г. |
20Наблюдать | CVE-2000-0678Эксплойта нет | PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificatpgp · pgp | Средняя5,0 | — | 1,5 % | 20 окт. 2000 г. |
20Наблюдать | CVE-2000-0543Эксплойта нет | The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not pgp · certificate server | Средняя5,0 | — | 1,1 % | 14 июн. 2000 г. |
19Наблюдать | CVE-2008-5731Proof of concept | The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause pgp · desktop · CWE-399 | Средняя4,9 | — | 0,9 % | 26 дек. 2008 г. |
18Наблюдать | CVE-2001-0381Эксплойта нет | The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters tpgp · openpgp | Средняя4,6 | — | 0,4 % | 27 июн. 2001 г. |
18Наблюдать | CVE-2001-0435Эксплойта нет | The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while pgp · pgp | Средняя4,6 | — | 0,3 % | 2 июл. 2001 г. |
17Наблюдать | CVE-2010-3618Эксплойта нет | PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" funcpgp · desktop for windows · CWE-310 | Средняя4,3 | — | 1,6 % | 22 нояб. 2010 г. |
14Наблюдать | CVE-2000-0802Эксплойта нет | The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain accesspgp · personal privacy | Низкая3,6 | — | 0,3 % | 20 окт. 2000 г. |
8Наблюдать | CVE-2001-0265Proof of concept | ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored fipgp · pgp | Низкая2,1 | — | 0,7 % | 18 июн. 2001 г. |
8Наблюдать | CVE-2005-4151Эксплойта нет | The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space inpgp · desktop | Низкая2,1 | — | 0,5 % | 10 дек. 2005 г. |
8Наблюдать | CVE-2000-0445Эксплойта нет | The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may propgp · pgp | Низкая2,1 | — | 0,4 % | 24 мая 2000 г. |
8Наблюдать | CVE-2002-1977Эксплойта нет | Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackpgp · pgp | Низкая2,1 | — | 0,4 % | 31 дек. 2002 г. |
- CVE-2001-132050В плане
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via ex
ВысокаяCVSS 7,5Готовый эксплойтEPSS 68 %pgp · keyserver16 июл. 2001 г.
- CVE-2001-125241В плане
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs t
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %pgp · keyserver28 сент. 2001 г.
- CVE-2010-339738Наблюдать
Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local user
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %pgp · desktop15 сент. 2010 г.
- CVE-2001-145632Наблюдать
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitra
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %mcafee · webshield smtp4 сент. 2001 г.
- CVE-2002-085031Наблюдать
Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long f
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %pgp · corporate desktop4 окт. 2002 г.
- CVE-2002-068531Наблюдать
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %pgp · desktop security23 июл. 2002 г.
- CVE-2002-206931Наблюдать
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to rec
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %pgp · personal privacy31 дек. 2002 г.
- CVE-2007-060330Наблюдать
PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgps
ВысокаяCVSS 7,1Эксплойта нетEPSS 5 %pgp · corporate desktop30 янв. 2007 г.
- CVE-2001-101630Наблюдать
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pgp · corporate desktop4 сент. 2001 г.
- CVE-2009-068128Наблюдать
PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) caus
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %pgp · desktop15 апр. 2009 г.
- CVE-2002-078822Наблюдать
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext
СредняяCVSS 5,5Эксплойта нетEPSS 0 %pgp · corporate desktop12 авг. 2002 г.
- CVE-2002-169622Наблюдать
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically de
СредняяCVSS 5,5Эксплойта нетEPSS 0 %pgp · personal privacy31 дек. 2002 г.
- CVE-2000-067820Наблюдать
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificat
СредняяCVSS 5,0Эксплойта нетEPSS 2 %pgp · pgp20 окт. 2000 г.
- CVE-2000-054320Наблюдать
The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not
СредняяCVSS 5,0Эксплойта нетEPSS 1 %pgp · certificate server14 июн. 2000 г.
- CVE-2008-573119Наблюдать
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause
СредняяCVSS 4,9Proof of conceptEPSS 1 %pgp · desktop26 дек. 2008 г.
- CVE-2001-038118Наблюдать
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters t
СредняяCVSS 4,6Эксплойта нетEPSS 0 %pgp · openpgp27 июн. 2001 г.
- CVE-2001-043518Наблюдать
The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while
СредняяCVSS 4,6Эксплойта нетEPSS 0 %pgp · pgp2 июл. 2001 г.
- CVE-2010-361817Наблюдать
PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" func
СредняяCVSS 4,3Эксплойта нетEPSS 2 %pgp · desktop for windows22 нояб. 2010 г.
- CVE-2000-080214Наблюдать
The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %pgp · personal privacy20 окт. 2000 г.
- CVE-2001-02658Наблюдать
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored fi
НизкаяCVSS 2,1Proof of conceptEPSS 1 %pgp · pgp18 июн. 2001 г.
- CVE-2005-41518Наблюдать
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pgp · desktop10 дек. 2005 г.
- CVE-2000-04458Наблюдать
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may pro
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pgp · pgp24 мая 2000 г.
- CVE-2002-19778Наблюдать
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attack
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pgp · pgp31 дек. 2002 г.