Citadel kayıtları
citadel üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %12,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-399 Resource Management Errors1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2004-1192Kavram kanıtı | Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via forcitadel · ux | Kritik10,0 | — | %11,7 | 10 Oca 2005 |
42Planlayın | CVE-2002-0432İstismar yok | Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of servicitadel · ux | Kritik10,0 | — | %5,6 | 26 Tem 2002 |
40Planlayın | CVE-2020-27739İstismar yok | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in ucitadel · webcit · CWE-613 | Kritik9,8 | — | %1,8 | 28 Eki 2020 |
34İzleyin | CVE-2008-0394Kavram kanıtı | Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which citadel · smtp · CWE-119 | Yüksek7,5 | — | %11,9 | 23 Oca 2008 |
31İzleyin | CVE-2007-3821İstismar yok | Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actcitadel · webcit | Yüksek7,5 | — | %2,7 | 16 Tem 2007 |
31İzleyin | CVE-2009-0364İstismar yok | Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackecitadel · webcit · CWE-134 | Yüksek7,5 | — | %2,6 | 26 Mar 2009 |
26İzleyin | CVE-2020-27742İstismar yok | An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else'scitadel · webcit · CWE-639 | Orta6,5 | — | %1,2 | 28 Eki 2020 |
24İzleyin | CVE-2020-27741İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or Hcitadel · webcit · CWE-79 | Orta6,1 | — | %1,1 | 28 Eki 2020 |
23İzleyin | CVE-2020-29547İstismar yok | An issue was discovered in Citadel through webcit-926.citadel · webcit · CWE-77 | Orta5,9 | — | %0,8 | 29 May 2023 |
21İzleyin | CVE-2004-1705Kavram kanıtı | Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.citadel · ux | Orta5,0 | — | %4,9 | 30 Tem 2004 |
21İzleyin | CVE-2011-1756İstismar yok | modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackecitadel · citadel · CWE-399 | Orta5,0 | — | %2,7 | 20 Haz 2011 |
21İzleyin | CVE-2020-27740İstismar yok | Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform.citadel · webcit | Orta5,3 | — | %1,3 | 28 Eki 2020 |
21İzleyin | CVE-2023-44272İstismar yok | A cross-site scripting vulnerability exists in Citadel versions prior to 994.citadel · citadel · CWE-79 | Orta5,4 | — | %0,4 | 4 Eki 2023 |
14İzleyin | CVE-2021-37845İstismar yok | An issue was discovered in Citadel through webcit-932.citadel · webcit | Düşük3,7 | — | %0,7 | 29 May 2023 |
11İzleyin | CVE-2007-3822Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via citadel · webcit | Düşük2,6 | — | %2,5 | 16 Tem 2007 |
8İzleyin | CVE-2004-1933İstismar yok | Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass citadel · ux | Düşük2,1 | — | %0,4 | 12 Nis 2004 |
- CVE-2004-119244Planlayın
Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via for
KritikCVSS 10,0Kavram kanıtıEPSS %12citadel · ux10 Oca 2005
- CVE-2002-043242Planlayın
Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of servi
KritikCVSS 10,0İstismar yokEPSS %6citadel · ux26 Tem 2002
- CVE-2020-2773940Planlayın
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u
KritikCVSS 9,8İstismar yokEPSS %2citadel · webcit28 Eki 2020
- CVE-2008-039434İzleyin
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which
YüksekCVSS 7,5Kavram kanıtıEPSS %12citadel · smtp23 Oca 2008
- CVE-2007-382131İzleyin
Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other act
YüksekCVSS 7,5İstismar yokEPSS %3citadel · webcit16 Tem 2007
- CVE-2009-036431İzleyin
Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attacke
YüksekCVSS 7,5İstismar yokEPSS %3citadel · webcit26 Mar 2009
- CVE-2020-2774226İzleyin
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's
OrtaCVSS 6,5İstismar yokEPSS %1citadel · webcit28 Eki 2020
- CVE-2020-2774124İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or H
OrtaCVSS 6,1İstismar yokEPSS %1citadel · webcit28 Eki 2020
- CVE-2020-2954723İzleyin
An issue was discovered in Citadel through webcit-926.
OrtaCVSS 5,9İstismar yokEPSS %1citadel · webcit29 May 2023
- CVE-2004-170521İzleyin
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
OrtaCVSS 5,0Kavram kanıtıEPSS %5citadel · ux30 Tem 2004
- CVE-2011-175621İzleyin
modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attacke
OrtaCVSS 5,0İstismar yokEPSS %3citadel · citadel20 Haz 2011
- CVE-2020-2774021İzleyin
Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform.
OrtaCVSS 5,3İstismar yokEPSS %1citadel · webcit28 Eki 2020
- CVE-2023-4427221İzleyin
A cross-site scripting vulnerability exists in Citadel versions prior to 994.
OrtaCVSS 5,4İstismar yokEPSS %0citadel · citadel4 Eki 2023
- CVE-2021-3784514İzleyin
An issue was discovered in Citadel through webcit-932.
DüşükCVSS 3,7İstismar yokEPSS %1citadel · webcit29 May 2023
- CVE-2007-382211İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via
DüşükCVSS 2,6Kavram kanıtıEPSS %2citadel · webcit16 Tem 2007
- CVE-2004-19338İzleyin
Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass
DüşükCVSS 2,1İstismar yokEPSS %0citadel · ux12 Nis 2004