cryptocat project kayıtları
cryptocat project üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-20 Improper Input Validation4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-331 Insufficient Entropy1
- CWE-326 Inadequate Encryption Strength1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2013-4103Kavram kanıtı | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user inputcryptocat project · cryptocat · CWE-20 | Kritik9,8 | — | %6,9 | 4 Kas 2019 |
40Planlayın | CVE-2013-2259İstismar yok | Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overviewcryptocat project · cryptocat · CWE-20 | Kritik9,8 | — | %3,7 | 4 Kas 2019 |
40Planlayın | CVE-2013-2260İstismar yok | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weaknesscryptocat project · cryptocat · CWE-331 | Kritik9,8 | — | %2,2 | 4 Kas 2019 |
39İzleyin | CVE-2013-4108İstismar yok | Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.cryptocat project · cryptocat | Kritik9,8 | — | %1,5 | 14 Kas 2019 |
37İzleyin | CVE-2013-4102İstismar yok | Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weaknesscryptocat project · cryptocat · CWE-330 | Kritik9,1 | — | %2,0 | 4 Kas 2019 |
33İzleyin | CVE-2013-2261Kavram kanıtı | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosurecryptocat project · cryptocat · CWE-200 | Yüksek7,5 | — | %11,6 | 4 Kas 2019 |
31İzleyin | CVE-2013-4100İstismar yok | Cryptocat before 2.0.22 has Remote Denial of Service via usernamecryptocat project · cryptocat · CWE-20 | Yüksek7,5 | — | %2,4 | 4 Kas 2019 |
31İzleyin | CVE-2013-2257İstismar yok | Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weaknesscryptocat project · cryptocat · CWE-307 | Yüksek7,5 | — | %2,0 | 4 Kas 2019 |
31İzleyin | CVE-2013-2262İstismar yok | Cryptocat strophe.js before 2.0.22 has information disclosurecryptocat project · cryptocat · CWE-200 | Yüksek7,5 | — | %1,9 | 4 Kas 2019 |
30İzleyin | CVE-2013-4105İstismar yok | Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosurecryptocat project · cryptocat · CWE-200 | Yüksek7,5 | — | %1,1 | 4 Kas 2019 |
30İzleyin | CVE-2013-4104İstismar yok | Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocolcryptocat project · cryptocat · CWE-326 | Yüksek7,5 | — | %0,8 | 4 Kas 2019 |
25İzleyin | CVE-2013-4109İstismar yok | An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.cryptocat project · cryptocat · CWE-79 | Orta6,1 | — | %1,7 | 14 Kas 2019 |
24İzleyin | CVE-2013-4106İstismar yok | A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.cryptocat project · cryptocat · CWE-79 | Orta6,1 | — | %1,5 | 14 Kas 2019 |
24İzleyin | CVE-2013-4107İstismar yok | Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scriptingcryptocat project · cryptocat · CWE-79 | Orta6,1 | — | %1,1 | 5 Kas 2019 |
22İzleyin | CVE-2013-4110İstismar yok | Cryptocat has an Unspecified Chat Participant User List Disclosurecryptocat project · cryptocat · CWE-200 | Orta5,3 | — | %2,0 | 5 Kas 2019 |
21İzleyin | CVE-2013-2258İstismar yok | Cryptocat before 2.0.22 has Nickname User Impersonationcryptocat project · cryptocat | Orta5,3 | — | %1,4 | 4 Kas 2019 |
21İzleyin | CVE-2013-4101İstismar yok | Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weaknesscryptocat project · cryptocat · CWE-20 | Orta5,3 | — | %1,4 | 4 Kas 2019 |
- CVE-2013-410341Planlayın
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
KritikCVSS 9,8Kavram kanıtıEPSS %7cryptocat project · cryptocat4 Kas 2019
- CVE-2013-225940Planlayın
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
KritikCVSS 9,8İstismar yokEPSS %4cryptocat project · cryptocat4 Kas 2019
- CVE-2013-226040Planlayın
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
KritikCVSS 9,8İstismar yokEPSS %2cryptocat project · cryptocat4 Kas 2019
- CVE-2013-410839İzleyin
Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.
KritikCVSS 9,8İstismar yokEPSS %2cryptocat project · cryptocat14 Kas 2019
- CVE-2013-410237İzleyin
Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
KritikCVSS 9,1İstismar yokEPSS %2cryptocat project · cryptocat4 Kas 2019
- CVE-2013-226133İzleyin
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
YüksekCVSS 7,5Kavram kanıtıEPSS %12cryptocat project · cryptocat4 Kas 2019
- CVE-2013-410031İzleyin
Cryptocat before 2.0.22 has Remote Denial of Service via username
YüksekCVSS 7,5İstismar yokEPSS %2cryptocat project · cryptocat4 Kas 2019
- CVE-2013-225731İzleyin
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
YüksekCVSS 7,5İstismar yokEPSS %2cryptocat project · cryptocat4 Kas 2019
- CVE-2013-226231İzleyin
Cryptocat strophe.js before 2.0.22 has information disclosure
YüksekCVSS 7,5İstismar yokEPSS %2cryptocat project · cryptocat4 Kas 2019
- CVE-2013-410530İzleyin
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %1cryptocat project · cryptocat4 Kas 2019
- CVE-2013-410430İzleyin
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
YüksekCVSS 7,5İstismar yokEPSS %1cryptocat project · cryptocat4 Kas 2019
- CVE-2013-410925İzleyin
An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
OrtaCVSS 6,1İstismar yokEPSS %2cryptocat project · cryptocat14 Kas 2019
- CVE-2013-410624İzleyin
A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
OrtaCVSS 6,1İstismar yokEPSS %1cryptocat project · cryptocat14 Kas 2019
- CVE-2013-410724İzleyin
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1cryptocat project · cryptocat5 Kas 2019
- CVE-2013-411022İzleyin
Cryptocat has an Unspecified Chat Participant User List Disclosure
OrtaCVSS 5,3İstismar yokEPSS %2cryptocat project · cryptocat5 Kas 2019
- CVE-2013-225821İzleyin
Cryptocat before 2.0.22 has Nickname User Impersonation
OrtaCVSS 5,3İstismar yokEPSS %1cryptocat project · cryptocat4 Kas 2019
- CVE-2013-410121İzleyin
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
OrtaCVSS 5,3İstismar yokEPSS %1cryptocat project · cryptocat4 Kas 2019