Записи rpath
19 опубликованных записей вендора rpath.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 63,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-399 Resource Management Errors2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2006-6235Эксплойта нет | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Критическая10,0 | — | 5,9 % | 7 дек. 2006 г. |
36Наблюдать | CVE-2007-1351Эксплойта нет | Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allx.org · libxfont · CWE-189 | Высокая8,5 | — | 5,6 % | 5 апр. 2007 г. |
32Наблюдать | CVE-2007-5962Proof of concept | Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresighredhat · enterprise linux · CWE-399 | Высокая7,1 | — | 12,1 % | 22 мая 2008 г. |
31Наблюдать | CVE-2008-0411Proof of concept | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrghostscript · ghostscript · CWE-119 | Средняя6,8 | — | 14,5 % | 28 февр. 2008 г. |
31Наблюдать | CVE-2007-5116Эксплойта нет | Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackerdebian · debian linux · CWE-119 | Высокая7,5 | — | 4,8 % | 7 нояб. 2007 г. |
31Наблюдать | CVE-2008-5516Эксплойта нет | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | Высокая7,5 | — | 4,4 % | 20 янв. 2009 г. |
28Наблюдать | CVE-2007-3106Эксплойта нет | lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service andlibvorbis · libvorbis · CWE-399 | Средняя6,8 | — | 3,1 % | 26 июл. 2007 г. |
28Наблюдать | CVE-2007-4131Эксплойта нет | Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrgnu · tar | Средняя6,8 | — | 2,7 % | 24 авг. 2007 г. |
28Наблюдать | CVE-2008-1078Эксплойта нет | expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files vgentoo · linux · CWE-59 | Высокая7,2 | — | 0,5 % | 28 февр. 2008 г. |
28Наблюдать | CVE-2007-0536Эксплойта нет | The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissirpath · rpath linux | Высокая7,2 | — | 0,4 % | 26 янв. 2007 г. |
27Наблюдать | CVE-2007-4029Эксплойта нет | libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalilibvorbis · libvorbis | Средняя6,8 | — | 1,7 % | 26 июл. 2007 г. |
27Наблюдать | CVE-2007-5194Эксплойта нет | The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device nrpath · rmake · CWE-264 | Средняя6,9 | — | 0,3 % | 4 окт. 2007 г. |
27Наблюдать | CVE-2008-4832Эксплойта нет | rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directorrpath · initscripts · CWE-59 | Средняя6,9 | — | 0,3 % | 17 нояб. 2008 г. |
26Наблюдать | CVE-2008-2139Эксплойта нет | The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session,rpath · appliance platform agent · CWE-264 | Средняя6,5 | — | 0,4 % | 12 мая 2008 г. |
21Наблюдать | CVE-2008-3139Эксплойта нет | The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via uwireshark · wireshark · CWE-200 | Средняя5,0 | — | 2,9 % | 10 июл. 2008 г. |
21Наблюдать | CVE-2008-3138Эксплойта нет | The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of serwireshark · wireshark · CWE-200 | Средняя5,0 | — | 2,0 % | 10 июл. 2008 г. |
19Наблюдать | CVE-2007-5686Эксплойта нет | initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information rpath · rpath linux · CWE-264 | Средняя4,9 | — | 0,9 % | 28 окт. 2007 г. |
15Наблюдать | CVE-2007-1352Эксплойта нет | Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary x.org · libxfont | Низкая3,8 | — | 1,5 % | 5 апр. 2007 г. |
10Наблюдать | CVE-2008-2140Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to rerpath · appliance platform agent · CWE-352 | Низкая2,6 | — | 0,4 % | 12 мая 2008 г. |
- CVE-2006-623542В плане
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %gnu · privacy guard7 дек. 2006 г.
- CVE-2007-135136Наблюдать
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier all
ВысокаяCVSS 8,5Эксплойта нетEPSS 6 %x.org · libxfont5 апр. 2007 г.
- CVE-2007-596232Наблюдать
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresigh
ВысокаяCVSS 7,1Proof of conceptEPSS 12 %redhat · enterprise linux22 мая 2008 г.
- CVE-2008-041131Наблюдать
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitr
СредняяCVSS 6,8Proof of conceptEPSS 15 %ghostscript · ghostscript28 февр. 2008 г.
- CVE-2007-511631Наблюдать
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %debian · debian linux7 нояб. 2007 г.
- CVE-2008-551631Наблюдать
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %git · git20 янв. 2009 г.
- CVE-2007-310628Наблюдать
lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and
СредняяCVSS 6,8Эксплойта нетEPSS 3 %libvorbis · libvorbis26 июл. 2007 г.
- CVE-2007-413128Наблюдать
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwr
СредняяCVSS 6,8Эксплойта нетEPSS 3 %gnu · tar24 авг. 2007 г.
- CVE-2008-107828Наблюдать
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files v
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %gentoo · linux28 февр. 2008 г.
- CVE-2007-053628Наблюдать
The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissi
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %rpath · rpath linux26 янв. 2007 г.
- CVE-2007-402927Наблюдать
libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invali
СредняяCVSS 6,8Эксплойта нетEPSS 2 %libvorbis · libvorbis26 июл. 2007 г.
- CVE-2007-519427Наблюдать
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device n
СредняяCVSS 6,9Эксплойта нетEPSS 0 %rpath · rmake4 окт. 2007 г.
- CVE-2008-483227Наблюдать
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a director
СредняяCVSS 6,9Эксплойта нетEPSS 0 %rpath · initscripts17 нояб. 2008 г.
- CVE-2008-213926Наблюдать
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session,
СредняяCVSS 6,5Эксплойта нетEPSS 0 %rpath · appliance platform agent12 мая 2008 г.
- CVE-2008-313921Наблюдать
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via u
СредняяCVSS 5,0Эксплойта нетEPSS 3 %wireshark · wireshark10 июл. 2008 г.
- CVE-2008-313821Наблюдать
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of ser
СредняяCVSS 5,0Эксплойта нетEPSS 2 %wireshark · wireshark10 июл. 2008 г.
- CVE-2007-568619Наблюдать
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information
СредняяCVSS 4,9Эксплойта нетEPSS 1 %rpath · rpath linux28 окт. 2007 г.
- CVE-2007-135215Наблюдать
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary
НизкаяCVSS 3,8Эксплойта нетEPSS 2 %x.org · libxfont5 апр. 2007 г.
- CVE-2008-214010Наблюдать
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to re
НизкаяCVSS 2,6Эксплойта нетEPSS 0 %rpath · appliance platform agent12 мая 2008 г.