ebay kayıtları
ebay üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2008-2475İstismar yok | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via tebay · enhanced picture uploader activex control · CWE-78 | Kritik9,3 | — | %4,1 | 9 Haz 2009 |
31İzleyin | CVE-2006-1176İstismar yok | Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Iteebay · enhanced picture services | Yüksek7,5 | — | %4,6 | 7 Tem 2006 |
31İzleyin | CVE-2023-26107İstismar yok | All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametriebay · sketchsvg · CWE-94 | Yüksek7,8 | — | %0,4 | 6 Mar 2023 |
11İzleyin | CVE-2010-4211İstismar yok | The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate,ebay · paypal · CWE-287 | Düşük2,9 | — | %0,4 | 8 Kas 2010 |
- CVE-2008-247538İzleyin
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via t
KritikCVSS 9,3İstismar yokEPSS %4ebay · enhanced picture uploader activex control9 Haz 2009
- CVE-2006-117631İzleyin
Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Ite
YüksekCVSS 7,5İstismar yokEPSS %5ebay · enhanced picture services7 Tem 2006
- CVE-2023-2610731İzleyin
All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametri
YüksekCVSS 7,8İstismar yokEPSS %0ebay · sketchsvg6 Mar 2023
- CVE-2010-421111İzleyin
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate,
DüşükCVSS 2,9İstismar yokEPSS %0ebay · paypal8 Kas 2010