cvs kayıtları
cvs üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-415 Double Free1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2004-0396Kavram kanıtı | Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers tocvs · cvs | Yüksek7,5 | — | %67,5 | 14 Haz 2004 |
44Planlayın | CVE-2004-0416Kavram kanıtı | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Kritik10,0 | — | %13,2 | 6 Ağu 2004 |
43Planlayın | CVE-2012-0804İstismar yok | Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a decvs · cvs · CWE-119 | Kritik10,0 | — | %8,5 | 29 May 2012 |
42Planlayın | CVE-2004-0418İstismar yok | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Kritik10,0 | — | %5,7 | 6 Ağu 2004 |
41Planlayın | CVE-2004-0414İstismar yok | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator frcvs · cvs | Kritik10,0 | — | %4,0 | 6 Ağu 2004 |
37İzleyin | CVE-2003-0015Kavram kanıtı | Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary codecvs · cvs · CWE-415 | Yüksek7,5 | — | %23,9 | 7 Şub 2003 |
31İzleyin | CVE-2005-0753İstismar yok | Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.cvs · cvs | Yüksek7,5 | — | %4,7 | 18 Nis 2005 |
31İzleyin | CVE-2003-0977İstismar yok | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via cvs · cvs | Yüksek7,5 | — | %2,3 | 5 Oca 2004 |
31İzleyin | CVE-2004-1342İstismar yok | CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acccvs · cvs | Yüksek7,5 | — | %2,3 | 27 Nis 2005 |
30İzleyin | CVE-2004-1471Kavram kanıtı | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commicvs · cvs | Yüksek7,1 | — | %7,7 | 31 Ara 2004 |
28İzleyin | CVE-2000-0680Kavram kanıtı | The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVScvs · cvs | Yüksek7,2 | — | %1,3 | 20 Eki 2000 |
21İzleyin | CVE-2004-0417İstismar yok | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may cvs · cvs | Orta5,0 | — | %3,1 | 6 Ağu 2004 |
21İzleyin | CVE-2004-0405İstismar yok | CVS before 1.11 allows CVS clients to read arbitrary files via ..cvs · cvs | Orta5,0 | — | %2,4 | 1 Haz 2004 |
21İzleyin | CVE-2004-1343İstismar yok | CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouicvs · cvs | Orta5,0 | — | %1,9 | 31 Ara 2004 |
21İzleyin | CVE-2002-0092İstismar yok | CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) cvs · cvs | Orta5,0 | — | %1,8 | 15 Mar 2002 |
18İzleyin | CVE-2005-2693İstismar yok | cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbicvs · cvs | Orta4,6 | — | %0,4 | 26 Ağu 2005 |
11İzleyin | CVE-2004-0180İstismar yok | The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolutecvs · cvs | Düşük2,6 | — | %1,8 | 1 Haz 2004 |
8İzleyin | CVE-2000-0679Kavram kanıtı | The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary cvs · cvs | Düşük2,1 | — | %0,7 | 20 Eki 2000 |
- CVE-2004-039650Planlayın
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %68cvs · cvs14 Haz 2004
- CVE-2004-041644Planlayın
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
KritikCVSS 10,0Kavram kanıtıEPSS %13cvs · cvs6 Ağu 2004
- CVE-2012-080443Planlayın
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a de
KritikCVSS 10,0İstismar yokEPSS %8cvs · cvs29 May 2012
- CVE-2004-041842Planlayın
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
KritikCVSS 10,0İstismar yokEPSS %6cvs · cvs6 Ağu 2004
- CVE-2004-041441Planlayın
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr
KritikCVSS 10,0İstismar yokEPSS %4cvs · cvs6 Ağu 2004
- CVE-2003-001537İzleyin
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code
YüksekCVSS 7,5Kavram kanıtıEPSS %24cvs · cvs7 Şub 2003
- CVE-2005-075331İzleyin
Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
YüksekCVSS 7,5İstismar yokEPSS %5cvs · cvs18 Nis 2005
- CVE-2003-097731İzleyin
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via
YüksekCVSS 7,5İstismar yokEPSS %2cvs · cvs5 Oca 2004
- CVE-2004-134231İzleyin
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acc
YüksekCVSS 7,5İstismar yokEPSS %2cvs · cvs27 Nis 2005
- CVE-2004-147130İzleyin
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi
YüksekCVSS 7,1Kavram kanıtıEPSS %8cvs · cvs31 Ara 2004
- CVE-2000-068028İzleyin
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS
YüksekCVSS 7,2Kavram kanıtıEPSS %1cvs · cvs20 Eki 2000
- CVE-2004-041721İzleyin
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may
OrtaCVSS 5,0İstismar yokEPSS %3cvs · cvs6 Ağu 2004
- CVE-2004-040521İzleyin
CVS before 1.11 allows CVS clients to read arbitrary files via ..
OrtaCVSS 5,0İstismar yokEPSS %2cvs · cvs1 Haz 2004
- CVE-2004-134321İzleyin
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repoui
OrtaCVSS 5,0İstismar yokEPSS %2cvs · cvs31 Ara 2004
- CVE-2002-009221İzleyin
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash)
OrtaCVSS 5,0İstismar yokEPSS %2cvs · cvs15 Mar 2002
- CVE-2005-269318İzleyin
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbi
OrtaCVSS 4,6İstismar yokEPSS %0cvs · cvs26 Ağu 2005
- CVE-2004-018011İzleyin
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute
DüşükCVSS 2,6İstismar yokEPSS %2cvs · cvs1 Haz 2004
- CVE-2000-06798İzleyin
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary
DüşükCVSS 2,1Kavram kanıtıEPSS %1cvs · cvs20 Eki 2000