keybase kayıtları
keybase üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-426 Untrusted Search Path1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-7249İstismar yok | In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one usekeybase · keybase · CWE-367 | Kritik9,8 | — | %2,5 | 31 Oca 2019 |
36İzleyin | CVE-2021-34422İstismar yok | Path traversal of file names in Keybase Client for Windowskeybase · keybase · CWE-22 | Kritik9,0 | — | %1,4 | 11 Kas 2021 |
31İzleyin | CVE-2018-18629Kavram kanıtı | An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux.keybase · keybase · CWE-426 | Yüksek7,8 | — | %1,5 | 20 Ara 2018 |
31İzleyin | CVE-2021-34426İstismar yok | Arbitrary command execution in Keybase Client for Windowskeybase · keybase | Yüksek7,8 | — | %0,2 | 14 Ara 2021 |
30İzleyin | CVE-2019-16992İstismar yok | The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocukeybase · keybase · CWE-347 | Yüksek7,5 | — | %0,9 | 29 Eyl 2019 |
22İzleyin | CVE-2021-23827İstismar yok | Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive medikeybase · keybase · CWE-312 | Orta5,5 | — | %0,3 | 22 Şub 2021 |
17İzleyin | CVE-2021-34421İstismar yok | Retained exploded messages in Keybase Clients for Android and iOSkeybase · keybase · CWE-459 | Orta4,3 | — | %0,7 | 11 Kas 2021 |
14İzleyin | CVE-2022-22779İstismar yok | Retained exploded messages in Keybase clients for macOS and Windowskeybase · keybase · CWE-212 | Düşük3,7 | — | %0,8 | 9 Şub 2022 |
- CVE-2019-724940Planlayın
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one use
KritikCVSS 9,8İstismar yokEPSS %3keybase · keybase31 Oca 2019
- CVE-2021-3442236İzleyin
Path traversal of file names in Keybase Client for Windows
KritikCVSS 9,0İstismar yokEPSS %1keybase · keybase11 Kas 2021
- CVE-2018-1862931İzleyin
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux.
YüksekCVSS 7,8Kavram kanıtıEPSS %1keybase · keybase20 Ara 2018
- CVE-2021-3442631İzleyin
Arbitrary command execution in Keybase Client for Windows
YüksekCVSS 7,8İstismar yokEPSS %0keybase · keybase14 Ara 2021
- CVE-2019-1699230İzleyin
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocu
YüksekCVSS 7,5İstismar yokEPSS %1keybase · keybase29 Eyl 2019
- CVE-2021-2382722İzleyin
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive medi
OrtaCVSS 5,5İstismar yokEPSS %0keybase · keybase22 Şub 2021
- CVE-2021-3442117İzleyin
Retained exploded messages in Keybase Clients for Android and iOS
OrtaCVSS 4,3İstismar yokEPSS %1keybase · keybase11 Kas 2021
- CVE-2022-2277914İzleyin
Retained exploded messages in Keybase clients for macOS and Windows
DüşükCVSS 3,7İstismar yokEPSS %1keybase · keybase9 Şub 2022