Записи Spotify
3 опубликованных записей вендора spotify.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 33,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
3 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2018-1167Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336.spotify · spotify · CWE-78 | Высокая8,8 | — | 4,6 % | 18 апр. 2018 г. |
35Наблюдать | CVE-2018-1000843Эксплойта нет | Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 containspotify · luigi · CWE-352 | Высокая8,8 | — | 0,8 % | 20 дек. 2018 г. |
30Наблюдать | CVE-2024-42011Эксплойта нет | The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.CWE-120 | Высокая7,5 | — | 0,6 % | 28 окт. 2024 г. |
- CVE-2018-116736Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336.
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %spotify · spotify18 апр. 2018 г.
- CVE-2018-100084335Наблюдать
Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contain
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %spotify · luigi20 дек. 2018 г.
- CVE-2024-4201130Наблюдать
The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %28 окт. 2024 г.