Записи uzbl
3 опубликованных записей вендора uzbl.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
3 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2010-0011Эксплойта нет | The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to exuzbl · uzbl · CWE-264 | Высокая7,5 | — | 2,1 % | 25 февр. 2010 г. |
29Наблюдать | CVE-2010-2809Proof of concept | The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows uuzbl · uzbl · CWE-94 | Средняя6,8 | — | 7,3 % | 19 авг. 2010 г. |
22Наблюдать | CVE-2012-0843Эксплойта нет | uzbl: Information disclosure via world-readable cookies storage fileuzbl · uzbl · CWE-200 | Средняя5,5 | — | 0,4 % | 19 нояб. 2019 г. |
- CVE-2010-001131Наблюдать
The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to ex
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %uzbl · uzbl25 февр. 2010 г.
- CVE-2010-280929Наблюдать
The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows u
СредняяCVSS 6,8Proof of conceptEPSS 7 %uzbl · uzbl19 авг. 2010 г.
- CVE-2012-084322Наблюдать
uzbl: Information disclosure via world-readable cookies storage file
СредняяCVSS 5,5Эксплойта нетEPSS 0 %uzbl · uzbl19 нояб. 2019 г.