Evernote kayıtları
evernote üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication2
- CWE-426 Untrusted Search Path1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-50643Kavram kanıtı | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspevernote · evernote | Kritik9,8 | — | %1,7 | 8 Oca 2024 |
36İzleyin | CVE-2020-17759İstismar yok | An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler.evernote · evernote · CWE-77 | Yüksek8,8 | — | %3,4 | 24 Haz 2021 |
31İzleyin | CVE-2019-17051İstismar yok | Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonevernote · evernote · CWE-732 | Yüksek7,8 | — | %1,6 | 30 Eyl 2019 |
31İzleyin | CVE-2016-4900İstismar yok | Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan hoevernote · evernote · CWE-426 | Yüksek7,8 | — | %1,5 | 22 May 2017 |
31İzleyin | CVE-2019-10038Kavram kanıtı | Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applicevernote · evernote · CWE-22 | Yüksek7,8 | — | %1,3 | 31 May 2019 |
30İzleyin | CVE-2018-20058İstismar yok | In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.evernote · evernote · CWE-22 | Yüksek7,5 | — | %1,4 | 11 Ara 2018 |
28İzleyin | CVE-2013-5116İstismar yok | Evernote prior to 5.5.1 has insecure password changeevernote · evernote · CWE-287 | Yüksek7,1 | — | %0,5 | 31 Oca 2020 |
25İzleyin | CVE-2018-18524İstismar yok | Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability.evernote · evernote · CWE-79 | Orta6,1 | — | %1,9 | 13 May 2019 |
24İzleyin | CVE-2019-12592İstismar yok | A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackersevernote · web clipper · CWE-79 | Orta6,1 | — | %1,1 | 18 Haz 2019 |
24İzleyin | CVE-2018-20351İstismar yok | The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.evernote · evernote · CWE-79 | Orta6,1 | — | %0,6 | 21 Ara 2018 |
21İzleyin | CVE-2018-19658İstismar yok | The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS.evernote · yinxiang biji · CWE-79 | Orta5,4 | — | %0,5 | 2 Mar 2020 |
18İzleyin | CVE-2013-5112İstismar yok | Evernote before 5.5.1 has insecure PIN storageevernote · evernote · CWE-287 | Orta4,6 | — | %0,5 | 31 Oca 2020 |
- CVE-2023-5064340Planlayın
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnsp
KritikCVSS 9,8Kavram kanıtıEPSS %2evernote · evernote8 Oca 2024
- CVE-2020-1775936İzleyin
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler.
YüksekCVSS 8,8İstismar yokEPSS %3evernote · evernote24 Haz 2021
- CVE-2019-1705131İzleyin
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demon
YüksekCVSS 7,8İstismar yokEPSS %2evernote · evernote30 Eyl 2019
- CVE-2016-490031İzleyin
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan ho
YüksekCVSS 7,8İstismar yokEPSS %2evernote · evernote22 May 2017
- CVE-2019-1003831İzleyin
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applic
YüksekCVSS 7,8Kavram kanıtıEPSS %1evernote · evernote31 May 2019
- CVE-2018-2005830İzleyin
In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.
YüksekCVSS 7,5İstismar yokEPSS %1evernote · evernote11 Ara 2018
- CVE-2013-511628İzleyin
Evernote prior to 5.5.1 has insecure password change
YüksekCVSS 7,1İstismar yokEPSS %0evernote · evernote31 Oca 2020
- CVE-2018-1852425İzleyin
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %2evernote · evernote13 May 2019
- CVE-2019-1259224İzleyin
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers
OrtaCVSS 6,1İstismar yokEPSS %1evernote · web clipper18 Haz 2019
- CVE-2018-2035124İzleyin
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.
OrtaCVSS 6,1İstismar yokEPSS %1evernote · evernote21 Ara 2018
- CVE-2018-1965821İzleyin
The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS.
OrtaCVSS 5,4İstismar yokEPSS %1evernote · yinxiang biji2 Mar 2020
- CVE-2013-511218İzleyin
Evernote before 5.5.1 has insecure PIN storage
OrtaCVSS 4,6İstismar yokEPSS %1evernote · evernote31 Oca 2020