Записи xfce
8 опубликованных записей вендора xfce.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
- CWE-913 Improper Control of Dynamically-Managed Code Resources1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-6532Эксплойта нет | Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code vixfce · xfce · CWE-119 | Критическая10,0 | — | 4,0 % | 9 янв. 2008 г. |
40В плане | CVE-2021-32563Эксплойта нет | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.xfce · thunar · CWE-913 | Критическая9,8 | — | 3,0 % | 11 мая 2021 г. |
39Наблюдать | CVE-2022-45062Эксплойта нет | In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.xfce · xfce4-settings · CWE-88 | Критическая9,8 | — | 1,5 % | 9 нояб. 2022 г. |
36Наблюдать | CVE-2022-32278Эксплойта нет | XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.xfce · exo | Высокая8,8 | — | 1,7 % | 13 июн. 2022 г. |
31Наблюдать | CVE-2011-1588Эксплойта нет | Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.xfce · thunar · CWE-134 | Высокая7,8 | — | 1,1 % | 13 нояб. 2019 г. |
28Наблюдать | CVE-2009-4996Эксплойта нет | Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physicxfce · xfce · CWE-264 | Высокая7,2 | — | 0,3 % | 7 сент. 2010 г. |
21Наблюдать | CVE-2007-6531Эксплойта нет | Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary codexfce · xfce · CWE-119 | Средняя5,0 | — | 2,9 % | 9 янв. 2008 г. |
18Наблюдать | CVE-2018-18398Эксплойта нет | Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an outxfce · thunar · CWE-125 | Средняя4,7 | — | 0,3 % | 19 окт. 2018 г. |
- CVE-2007-653241В плане
Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code vi
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %xfce · xfce9 янв. 2008 г.
- CVE-2021-3256340В плане
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xfce · thunar11 мая 2021 г.
- CVE-2022-4506239Наблюдать
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xfce · xfce4-settings9 нояб. 2022 г.
- CVE-2022-3227836Наблюдать
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %xfce · exo13 июн. 2022 г.
- CVE-2011-158831Наблюдать
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xfce · thunar13 нояб. 2019 г.
- CVE-2009-499628Наблюдать
Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physic
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %xfce · xfce7 сент. 2010 г.
- CVE-2007-653121Наблюдать
Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code
СредняяCVSS 5,0Эксплойта нетEPSS 3 %xfce · xfce9 янв. 2008 г.
- CVE-2018-1839818Наблюдать
Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out
СредняяCVSS 4,7Эксплойта нетEPSS 0 %xfce · thunar19 окт. 2018 г.