Записи systemtap
12 опубликованных записей вендора systemtap.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 8,3 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-189 Numeric Errors3
- CWE-20 Improper Input Validation3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2009-4273Proof of concept | stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line argusystemtap · systemtap · CWE-94 | Критическая10,0 | — | 17,7 % | 26 янв. 2010 г. |
31Наблюдать | CVE-2010-0412Эксплойта нет | stap-server in SystemTap 1.1 does not properly restrict the value of the -B (aka BUILD) option, which allows attackers to have an unspecifiesystemtap · systemtap | Высокая7,5 | — | 1,7 % | 24 февр. 2010 г. |
30Наблюдать | CVE-2010-4170Готовый эксплойт | The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gaisystemtap · systemtap · CWE-264 | Высокая7,2 | — | 5,3 % | 7 дек. 2010 г. |
25Наблюдать | CVE-2009-0784Эксплойта нет | Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTasystemtap · systemtap · CWE-362 | Средняя6,3 | — | 0,3 % | 25 мар. 2009 г. |
21Наблюдать | CVE-2012-0875Эксплойта нет | SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information frosystemtap · systemtap · CWE-264 | Средняя5,4 | — | 0,4 % | 4 февр. 2014 г. |
19Наблюдать | CVE-2010-0411Proof of concept | Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allsystemtap · systemtap · CWE-189 | Средняя4,9 | — | 0,9 % | 8 февр. 2010 г. |
17Наблюдать | CVE-2011-2502Эксплойта нет | runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a mosystemtap · systemtap · CWE-20 | Средняя4,4 | — | 0,5 % | 26 июл. 2012 г. |
14Наблюдать | CVE-2011-2503Эксплойта нет | The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not propesystemtap · systemtap · CWE-20 | Низкая3,7 | — | 0,4 % | 26 июл. 2012 г. |
8Наблюдать | CVE-2010-4171Эксплойта нет | The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local usesystemtap · systemtap · CWE-20 | Низкая2,1 | — | 0,4 % | 7 дек. 2010 г. |
7Наблюдать | CVE-2009-2911Эксплойта нет | SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause systemtap · systemtap · CWE-264 | Низкая1,9 | — | 0,5 % | 22 окт. 2009 г. |
4Наблюдать | CVE-2011-1781Эксплойта нет | SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOsystemtap · systemtap · CWE-189 | Низкая1,2 | — | 0,3 % | 29 авг. 2011 г. |
4Наблюдать | CVE-2011-1769Эксплойта нет | SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero systemtap · systemtap · CWE-189 | Низкая1,2 | — | 0,3 % | 29 авг. 2011 г. |
- CVE-2009-427345В плане
stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line argu
КритическаяCVSS 10,0Proof of conceptEPSS 18 %systemtap · systemtap26 янв. 2010 г.
- CVE-2010-041231Наблюдать
stap-server in SystemTap 1.1 does not properly restrict the value of the -B (aka BUILD) option, which allows attackers to have an unspecifie
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %systemtap · systemtap24 февр. 2010 г.
- CVE-2010-417030Наблюдать
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gai
ВысокаяCVSS 7,2Готовый эксплойтEPSS 5 %systemtap · systemtap7 дек. 2010 г.
- CVE-2009-078425Наблюдать
Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTa
СредняяCVSS 6,3Эксплойта нетEPSS 0 %systemtap · systemtap25 мар. 2009 г.
- CVE-2012-087521Наблюдать
SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information fro
СредняяCVSS 5,4Эксплойта нетEPSS 0 %systemtap · systemtap4 февр. 2014 г.
- CVE-2010-041119Наблюдать
Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 all
СредняяCVSS 4,9Proof of conceptEPSS 1 %systemtap · systemtap8 февр. 2010 г.
- CVE-2011-250217Наблюдать
runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a mo
СредняяCVSS 4,4Эксплойта нетEPSS 1 %systemtap · systemtap26 июл. 2012 г.
- CVE-2011-250314Наблюдать
The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not prope
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %systemtap · systemtap26 июл. 2012 г.
- CVE-2010-41718Наблюдать
The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local use
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %systemtap · systemtap7 дек. 2010 г.
- CVE-2009-29117Наблюдать
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause
НизкаяCVSS 1,9Эксплойта нетEPSS 0 %systemtap · systemtap22 окт. 2009 г.
- CVE-2011-17814Наблюдать
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OO
НизкаяCVSS 1,2Эксплойта нетEPSS 0 %systemtap · systemtap29 авг. 2011 г.
- CVE-2011-17694Наблюдать
SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero
НизкаяCVSS 1,2Эксплойта нетEPSS 0 %systemtap · systemtap29 авг. 2011 г.