conversejs kayıtları
conversejs üreticisine ait 2 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
2 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
23İzleyin | CVE-2017-5858İstismar yok | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, includconversejs · converse.js · CWE-20 | Orta5,9 | — | %0,9 | 9 Şub 2017 |
21İzleyin | CVE-2018-6591İstismar yok | Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whethconversejs · converse.js · CWE-200 | Orta5,3 | — | %1,1 | 19 Şub 2018 |
- CVE-2017-585823İzleyin
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, includ
OrtaCVSS 5,9İstismar yokEPSS %1conversejs · converse.js9 Şub 2017
- CVE-2018-659121İzleyin
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine wheth
OrtaCVSS 5,3İstismar yokEPSS %1conversejs · converse.js19 Şub 2018