Записи squareup
12 опубликованных записей вендора squareup.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 66,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-295 Improper Certificate Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2015-8969Эксплойта нет | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.squareup · git-fastclone · CWE-77 | Критическая9,8 | — | 4,8 % | 3 нояб. 2016 г. |
39Наблюдать | CVE-2020-36645Эксплойта нет | square squalor sql injectionsquareup · squalor · CWE-89 | Критическая9,8 | — | 0,7 % | 7 янв. 2023 г. |
37Наблюдать | CVE-2015-8968Эксплойта нет | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.squareup · git-fastclone · CWE-77 | Высокая8,8 | — | 5,2 % | 3 нояб. 2016 г. |
37Наблюдать | CVE-2018-1000844Proof of concept | Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabilsquareup · retrofit · CWE-611 | Критическая9,1 | — | 2,2 % | 20 дек. 2018 г. |
31Наблюдать | CVE-2018-1000850Proof of concept | Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder csquareup · retrofit · CWE-22 | Высокая7,5 | — | 4,0 % | 20 дек. 2018 г. |
30Наблюдать | CVE-2023-3635Proof of concept | Okio GzipSource unhandled exception Denial of Servicesquareup · okio · CWE-195 | Высокая7,5 | — | 1,3 % | 12 июл. 2023 г. |
30Наблюдать | CVE-2026-45799Эксплойта нет | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding servicesquareup · wire · CWE-129 | Высокая7,5 | — | 0,7 % | 17 июл. 2026 г. |
24Наблюдать | CVE-2018-20200Эксплойта нет | CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext squareup · okhttp · CWE-295 | Средняя5,9 | — | 2,5 % | 18 апр. 2019 г. |
24Наблюдать | CVE-2016-2402Proof of concept | OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain witsquareup · okhttp · CWE-295 | Средняя5,9 | — | 2,2 % | 30 янв. 2017 г. |
23Наблюдать | CVE-2023-3782Эксплойта нет | DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb squareup · okhttp-brotli · CWE-400 | Средняя5,9 | — | 0,7 % | 19 июл. 2023 г. |
22Наблюдать | CVE-2023-0833Эксплойта нет | Red hat a-mq streams: component version with information disclosure flawsquareup · okhttp · CWE-209 | Средняя5,5 | — | 0,4 % | 27 сент. 2023 г. |
13Наблюдать | CVE-2021-23331Эксплойта нет | Insecure Temporary Filesquareup · connect java software development kit | Низкая3,3 | — | 0,3 % | 3 февр. 2021 г. |
- CVE-2015-896940В плане
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %squareup · git-fastclone3 нояб. 2016 г.
- CVE-2020-3664539Наблюдать
square squalor sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %squareup · squalor7 янв. 2023 г.
- CVE-2015-896837Наблюдать
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %squareup · git-fastclone3 нояб. 2016 г.
- CVE-2018-100084437Наблюдать
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabil
КритическаяCVSS 9,1Proof of conceptEPSS 2 %squareup · retrofit20 дек. 2018 г.
- CVE-2018-100085031Наблюдать
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder c
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %squareup · retrofit20 дек. 2018 г.
- CVE-2023-363530Наблюдать
Okio GzipSource unhandled exception Denial of Service
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %squareup · okio12 июл. 2023 г.
- CVE-2026-4579930Наблюдать
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %squareup · wire17 июл. 2026 г.
- CVE-2018-2020024Наблюдать
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext
СредняяCVSS 5,9Эксплойта нетEPSS 2 %squareup · okhttp18 апр. 2019 г.
- CVE-2016-240224Наблюдать
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain wit
СредняяCVSS 5,9Proof of conceptEPSS 2 %squareup · okhttp30 янв. 2017 г.
- CVE-2023-378223Наблюдать
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb
СредняяCVSS 5,9Эксплойта нетEPSS 1 %squareup · okhttp-brotli19 июл. 2023 г.
- CVE-2023-083322Наблюдать
Red hat a-mq streams: component version with information disclosure flaw
СредняяCVSS 5,5Эксплойта нетEPSS 0 %squareup · okhttp27 сент. 2023 г.
- CVE-2021-2333113Наблюдать
Insecure Temporary File
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %squareup · connect java software development kit3 февр. 2021 г.