dino kayıtları
dino üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-346 Origin Validation Error2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2019-16236İstismar yok | Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.dino · dino · CWE-862 | Yüksek7,5 | — | %2,4 | 11 Eyl 2019 |
30İzleyin | CVE-2019-16235İstismar yok | Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.dino · dino · CWE-346 | Yüksek7,5 | — | %1,4 | 11 Eyl 2019 |
30İzleyin | CVE-2019-16237İstismar yok | Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.dino · dino · CWE-346 | Yüksek7,5 | — | %1,2 | 11 Eyl 2019 |
28İzleyin | CVE-2008-4075Kavram kanıtı | Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a ..dino · d-iscussion board · CWE-22 | Orta6,8 | — | %1,9 | 15 Eyl 2008 |
28İzleyin | CVE-2023-28686İstismar yok | Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message.dino · dino · CWE-639 | Yüksek7,1 | — | %0,7 | 24 Mar 2023 |
22İzleyin | CVE-2021-33896İstismar yok | Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.dino · dino · CWE-22 | Orta5,3 | — | %1,8 | 7 Haz 2021 |
- CVE-2019-1623631İzleyin
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
YüksekCVSS 7,5İstismar yokEPSS %2dino · dino11 Eyl 2019
- CVE-2019-1623530İzleyin
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
YüksekCVSS 7,5İstismar yokEPSS %1dino · dino11 Eyl 2019
- CVE-2019-1623730İzleyin
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
YüksekCVSS 7,5İstismar yokEPSS %1dino · dino11 Eyl 2019
- CVE-2008-407528İzleyin
Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a ..
OrtaCVSS 6,8Kavram kanıtıEPSS %2dino · d-iscussion board15 Eyl 2008
- CVE-2023-2868628İzleyin
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message.
YüksekCVSS 7,1İstismar yokEPSS %1dino · dino24 Mar 2023
- CVE-2021-3389622İzleyin
Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.
OrtaCVSS 5,3İstismar yokEPSS %2dino · dino7 Haz 2021