cmu kayıtları
cmu üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %62,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-189 Numeric Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-1999-0799İstismar yok | Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.cmu · bootpd | Kritik10,0 | — | %1,9 | 1 Haz 1997 |
37İzleyin | CVE-2022-31506İstismar yok | The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used cmu · opendiamond · CWE-22 | Kritik9,3 | — | %1,5 | 10 Tem 2022 |
34İzleyin | CVE-2025-27092İstismar yok | Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpointcmu · ghosts · CWE-22 | Yüksek8,7 | — | %0,6 | 19 Şub 2025 |
32İzleyin | CVE-2011-3208İstismar yok | Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 alcmu · cyrus imap server · CWE-119 | Yüksek7,5 | — | %5,4 | 14 Eyl 2011 |
31İzleyin | CVE-2009-0663İstismar yok | Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to exeperl · perl · CWE-119 | Yüksek7,5 | — | %4,3 | 30 Nis 2009 |
30İzleyin | CVE-2026-35467İstismar yok | Private Key stored as extractable in browser IndexeDBcmu · cveclient · CWE-522 | Yüksek7,5 | — | %0,3 | 2 Nis 2026 |
27İzleyin | CVE-2026-22189İstismar yok | Panda3D <= 1.10.16 egg-mkfont Stack Buffer Overflowcmu · panda3d · CWE-121 | Orta6,9 | — | %0,5 | 7 Oca 2026 |
27İzleyin | CVE-2026-22188İstismar yok | Panda3D <= 1.10.16 Deploy-Stub Stack Exhaustion via Unbounded alloca()cmu · panda3d · CWE-457 | Orta6,9 | — | %0,2 | 7 Oca 2026 |
24İzleyin | CVE-2026-35466İstismar yok | Stored XSS via unsanitized input from remote servicecmu · cveclient · CWE-79 | Orta6,1 | — | %0,3 | 2 Nis 2026 |
21İzleyin | CVE-2011-1926İstismar yok | The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attaccmu · cyrus imap server · CWE-264 | Orta5,1 | — | %4,0 | 23 May 2011 |
21İzleyin | CVE-2014-7723İstismar yok | The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, cmu · carnegie mellon silicon valley · CWE-310 | Orta5,4 | — | %0,3 | 21 Eki 2014 |
20İzleyin | CVE-2026-22190İstismar yok | Panda3D <= 1.10.16 egg-mkfont Format String Information Disclosurecmu · panda3d · CWE-134 | Orta5,1 | — | %0,4 | 7 Oca 2026 |
18İzleyin | CVE-2013-4122İstismar yok | Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemecmu · cyrus-sasl · CWE-189 | Orta4,3 | — | %3,6 | 26 Eki 2013 |
18İzleyin | CVE-2011-3481İstismar yok | The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attacmu · cyrus imap server | Orta4,3 | — | %2,1 | 14 Eyl 2011 |
17İzleyin | CVE-2009-2632İstismar yok | Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1cmu · cyrus imap server · CWE-119 | Orta4,4 | — | %0,5 | 8 Eyl 2009 |
13İzleyin | CVE-2014-0027İstismar yok | The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmcmu · flite · CWE-59 | Düşük3,3 | — | %0,3 | 25 Oca 2014 |
- CVE-1999-079941Planlayın
Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.
KritikCVSS 10,0İstismar yokEPSS %2cmu · bootpd1 Haz 1997
- CVE-2022-3150637İzleyin
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used
KritikCVSS 9,3İstismar yokEPSS %2cmu · opendiamond10 Tem 2022
- CVE-2025-2709234İzleyin
Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint
YüksekCVSS 8,7İstismar yokEPSS %1cmu · ghosts19 Şub 2025
- CVE-2011-320832İzleyin
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 al
YüksekCVSS 7,5İstismar yokEPSS %5cmu · cyrus imap server14 Eyl 2011
- CVE-2009-066331İzleyin
Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to exe
YüksekCVSS 7,5İstismar yokEPSS %4perl · perl30 Nis 2009
- CVE-2026-3546730İzleyin
Private Key stored as extractable in browser IndexeDB
YüksekCVSS 7,5İstismar yokEPSS %0cmu · cveclient2 Nis 2026
- CVE-2026-2218927İzleyin
Panda3D <= 1.10.16 egg-mkfont Stack Buffer Overflow
OrtaCVSS 6,9İstismar yokEPSS %1cmu · panda3d7 Oca 2026
- CVE-2026-2218827İzleyin
Panda3D <= 1.10.16 Deploy-Stub Stack Exhaustion via Unbounded alloca()
OrtaCVSS 6,9İstismar yokEPSS %0cmu · panda3d7 Oca 2026
- CVE-2026-3546624İzleyin
Stored XSS via unsanitized input from remote service
OrtaCVSS 6,1İstismar yokEPSS %0cmu · cveclient2 Nis 2026
- CVE-2011-192621İzleyin
The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attac
OrtaCVSS 5,1İstismar yokEPSS %4cmu · cyrus imap server23 May 2011
- CVE-2014-772321İzleyin
The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers,
OrtaCVSS 5,4İstismar yokEPSS %0cmu · carnegie mellon silicon valley21 Eki 2014
- CVE-2026-2219020İzleyin
Panda3D <= 1.10.16 egg-mkfont Format String Information Disclosure
OrtaCVSS 5,1İstismar yokEPSS %0cmu · panda3d7 Oca 2026
- CVE-2013-412218İzleyin
Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as impleme
OrtaCVSS 4,3İstismar yokEPSS %4cmu · cyrus-sasl26 Eki 2013
- CVE-2011-348118İzleyin
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote atta
OrtaCVSS 4,3İstismar yokEPSS %2cmu · cyrus imap server14 Eyl 2011
- CVE-2009-263217İzleyin
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1
OrtaCVSS 4,4İstismar yokEPSS %0cmu · cyrus imap server8 Eyl 2009
- CVE-2014-002713İzleyin
The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tm
DüşükCVSS 3,3İstismar yokEPSS %0cmu · flite25 Oca 2014