Записи wesnoth
10 опубликованных записей вендора wesnoth.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 90 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-399 Resource Management Errors2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2009-0367Proof of concept | The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by usinwesnoth · wesnoth · CWE-264 | Критическая9,3 | — | 10,9 % | 4 мар. 2009 г. |
37Наблюдать | CVE-2007-5742Эксплойта нет | Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attawesnoth · wesnoth · CWE-22 | Критическая9,0 | — | 2,8 % | 1 дек. 2007 г. |
36Наблюдать | CVE-2018-1999023Эксплойта нет | The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can reswesnoth · the battle for wesnoth · CWE-94 | Высокая8,8 | — | 1,7 % | 23 июл. 2018 г. |
32Наблюдать | CVE-2007-3917Эксплойта нет | The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via awesnoth · wesnoth · CWE-134 | Высокая7,8 | — | 2,1 % | 11 окт. 2007 г. |
30Наблюдать | CVE-2007-6201Эксплойта нет | Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via awesnoth · wesnoth | Высокая7,5 | — | 1,5 % | 1 дек. 2007 г. |
21Наблюдать | CVE-2015-0844Эксплойта нет | The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crwesnoth · battle for wesnoth · CWE-200 | Средняя5,0 | — | 2,3 % | 14 апр. 2015 г. |
21Наблюдать | CVE-2009-0878Эксплойта нет | The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memwesnoth · wesnoth · CWE-399 | Средняя5,0 | — | 1,8 % | 12 мар. 2009 г. |
18Наблюдать | CVE-2009-0366Эксплойта нет | The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service viwesnoth · wesnoth · CWE-399 | Средняя4,3 | — | 2,0 % | 12 мар. 2009 г. |
18Наблюдать | CVE-2015-5069Эксплойта нет | The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnothwesnoth · battle for wesnoth · CWE-200 | Средняя4,3 | — | 1,7 % | 26 сент. 2017 г. |
12Наблюдать | CVE-2015-5070Эксплойта нет | The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnothwesnoth · battle for wesnoth · CWE-200 | Низкая3,1 | — | 1,4 % | 26 сент. 2017 г. |
- CVE-2009-036740В плане
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by usin
КритическаяCVSS 9,3Proof of conceptEPSS 11 %wesnoth · wesnoth4 мар. 2009 г.
- CVE-2007-574237Наблюдать
Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote atta
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %wesnoth · wesnoth1 дек. 2007 г.
- CVE-2018-199902336Наблюдать
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can res
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %wesnoth · the battle for wesnoth23 июл. 2018 г.
- CVE-2007-391732Наблюдать
The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %wesnoth · wesnoth11 окт. 2007 г.
- CVE-2007-620130Наблюдать
Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %wesnoth · wesnoth1 дек. 2007 г.
- CVE-2015-084421Наблюдать
The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a cr
СредняяCVSS 5,0Эксплойта нетEPSS 2 %wesnoth · battle for wesnoth14 апр. 2015 г.
- CVE-2009-087821Наблюдать
The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (mem
СредняяCVSS 5,0Эксплойта нетEPSS 2 %wesnoth · wesnoth12 мар. 2009 г.
- CVE-2009-036618Наблюдать
The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service vi
СредняяCVSS 4,3Эксплойта нетEPSS 2 %wesnoth · wesnoth12 мар. 2009 г.
- CVE-2015-506918Наблюдать
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth
СредняяCVSS 4,3Эксплойта нетEPSS 2 %wesnoth · battle for wesnoth26 сент. 2017 г.
- CVE-2015-507012Наблюдать
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth
НизкаяCVSS 3,1Эксплойта нетEPSS 1 %wesnoth · battle for wesnoth26 сент. 2017 г.