audacityteam kayıtları
audacityteam üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-276 Incorrect Default Permissions1
- CWE-427 Uncontrolled Search Path Element1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2009-0490Kavram kanıtı | Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other veaudacityteam · audacity · CWE-787 | Kritik9,3 | — | %16,6 | 9 Şub 2009 |
32İzleyin | CVE-2017-1000010İstismar yok | Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.audacityteam · audacity · CWE-427 | Yüksek7,8 | — | %2,1 | 17 Tem 2017 |
23İzleyin | CVE-2016-2540İstismar yok | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUaudacityteam · audacity · CWE-119 | Orta5,5 | — | %1,9 | 7 Şub 2018 |
22İzleyin | CVE-2016-2541İstismar yok | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.audacityteam · audacity · CWE-119 | Orta5,5 | — | %1,1 | 7 Şub 2018 |
21İzleyin | CVE-2007-6061İstismar yok | Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allowsaudacityteam · audacity · CWE-59 | Orta5,0 | — | %3,4 | 20 Kas 2007 |
13İzleyin | CVE-2020-11867İstismar yok | Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.audacityteam · audacity · CWE-276 | Düşük3,3 | — | %0,5 | 30 Kas 2020 |
- CVE-2009-049042Planlayın
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other ve
KritikCVSS 9,3Kavram kanıtıEPSS %17audacityteam · audacity9 Şub 2009
- CVE-2017-100001032İzleyin
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
YüksekCVSS 7,8İstismar yokEPSS %2audacityteam · audacity17 Tem 2017
- CVE-2016-254023İzleyin
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHU
OrtaCVSS 5,5İstismar yokEPSS %2audacityteam · audacity7 Şub 2018
- CVE-2016-254122İzleyin
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
OrtaCVSS 5,5İstismar yokEPSS %1audacityteam · audacity7 Şub 2018
- CVE-2007-606121İzleyin
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows
OrtaCVSS 5,0İstismar yokEPSS %3audacityteam · audacity20 Kas 2007
- CVE-2020-1186713İzleyin
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.
DüşükCVSS 3,3İstismar yokEPSS %0audacityteam · audacity30 Kas 2020