mageia kayıtları
mageia üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %9,1
- Silahlaştırılmış
- 3 · %13,6
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %95,5
- Yayından KEV’e ortanca
- 2683 gün
Tekrar eden sınıflar
- CWE-399 Resource Management Errors5
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
43Planlayın | CVE-2014-3566Silahlaştırılmış | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Düşük3,4 | — | %100,0 | 14 Eki 2014 |
32İzleyin | CVE-2014-9087İstismar yok | Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of segnupg · libksba · CWE-191 | Yüksek7,5 | — | %5,7 | 1 Ara 2014 |
31İzleyin | CVE-2013-4159İstismar yok | ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fiopensuse · opensuse · CWE-264 | Yüksek7,5 | — | %2,4 | 6 Ağu 2014 |
28İzleyin | CVE-2014-3429İstismar yok | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute aripython · ipython notebook · CWE-94 | Orta6,8 | — | %4,7 | 7 Ağu 2014 |
28İzleyin | CVE-2014-8104İstismar yok | OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service openvpn · openvpn · CWE-399 | Orta6,8 | — | %3,5 | 3 Ara 2014 |
24İzleyin | CVE-2014-5461İstismar yok | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial lua · lua · CWE-119 | Orta5,0 | — | %11,7 | 4 Eyl 2014 |
23İzleyin | CVE-2014-9116İstismar yok | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote amutt · mutt · CWE-119 | Orta5,0 | — | %9,7 | 2 Ara 2014 |
23İzleyin | CVE-2014-9637İstismar yok | GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted dgnu · patch · CWE-399 | Orta5,5 | — | %2,4 | 25 Ağu 2017 |
22İzleyin | CVE-2014-8117İstismar yok | softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumptifile project · file · CWE-399 | Orta5,0 | — | %5,9 | 17 Ara 2014 |
21İzleyin | CVE-2015-2189İstismar yok | Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x befwireshark · wireshark · CWE-189 | Orta5,0 | — | %4,6 | 7 Mar 2015 |
21İzleyin | CVE-2014-8116İstismar yok | The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large nfile project · file · CWE-399 | Orta5,0 | — | %4,4 | 17 Ara 2014 |
21İzleyin | CVE-2015-2188İstismar yok | epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize awireshark · wireshark · CWE-19 | Orta5,0 | — | %4,4 | 7 Mar 2015 |
21İzleyin | CVE-2014-7204İstismar yok | jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cracanonical · ubuntu linux · CWE-399 | Orta5,0 | — | %4,3 | 7 Eki 2014 |
21İzleyin | CVE-2015-2191İstismar yok | Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and wireshark · wireshark · CWE-189 | Orta5,0 | — | %3,9 | 7 Mar 2015 |
21İzleyin | CVE-2014-1829İstismar yok | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirepython · requests · CWE-200 | Orta5,0 | — | %2,2 | 15 Eki 2014 |
18İzleyin | CVE-2014-9253İstismar yok | The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers dokuwiki · dokuwiki · CWE-79 | Orta4,3 | — | %2,4 | 17 Ara 2014 |
15İzleyin | CVE-2015-0236İstismar yok | libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)mageia · mageia · CWE-200 | Düşük3,5 | — | %1,8 | 29 Oca 2015 |
13İzleyin | CVE-2014-2524İstismar yok | The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlinkgnu · readline · CWE-59 | Düşük3,3 | — | %0,4 | 20 Ağu 2014 |
8İzleyin | CVE-2014-3532İstismar yok | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service linux · linux kernel · CWE-20 | Düşük2,1 | — | %0,4 | 19 Tem 2014 |
8İzleyin | CVE-2014-8136İstismar yok | The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when amageia · mageia · CWE-264 | Düşük2,1 | — | %0,4 | 19 Ara 2014 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-356643Planlayın
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
DüşükCVSS 3,4SilahlaştırılmışEPSS %100openssl · openssl14 Eki 2014
- CVE-2014-908732İzleyin
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of se
YüksekCVSS 7,5İstismar yokEPSS %6gnupg · libksba1 Ara 2014
- CVE-2013-415931İzleyin
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fi
YüksekCVSS 7,5İstismar yokEPSS %2opensuse · opensuse6 Ağu 2014
- CVE-2014-342928İzleyin
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute ar
OrtaCVSS 6,8İstismar yokEPSS %5ipython · ipython notebook7 Ağu 2014
- CVE-2014-810428İzleyin
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service
OrtaCVSS 6,8İstismar yokEPSS %3openvpn · openvpn3 Ara 2014
- CVE-2014-546124İzleyin
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
OrtaCVSS 5,0İstismar yokEPSS %12lua · lua4 Eyl 2014
- CVE-2014-911623İzleyin
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote a
OrtaCVSS 5,0İstismar yokEPSS %10mutt · mutt2 Ara 2014
- CVE-2014-963723İzleyin
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted d
OrtaCVSS 5,5İstismar yokEPSS %2gnu · patch25 Ağu 2017
- CVE-2014-811722İzleyin
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumpti
OrtaCVSS 5,0İstismar yokEPSS %6file project · file17 Ara 2014
- CVE-2015-218921İzleyin
Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x bef
OrtaCVSS 5,0İstismar yokEPSS %5wireshark · wireshark7 Mar 2015
- CVE-2014-811621İzleyin
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large n
OrtaCVSS 5,0İstismar yokEPSS %4file project · file17 Ara 2014
- CVE-2015-218821İzleyin
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a
OrtaCVSS 5,0İstismar yokEPSS %4wireshark · wireshark7 Mar 2015
- CVE-2014-720421İzleyin
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cra
OrtaCVSS 5,0İstismar yokEPSS %4canonical · ubuntu linux7 Eki 2014
- CVE-2015-219121İzleyin
Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and
OrtaCVSS 5,0İstismar yokEPSS %4wireshark · wireshark7 Mar 2015
- CVE-2014-182921İzleyin
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redire
OrtaCVSS 5,0İstismar yokEPSS %2python · requests15 Eki 2014
- CVE-2014-925318İzleyin
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers
OrtaCVSS 4,3İstismar yokEPSS %2dokuwiki · dokuwiki17 Ara 2014
- CVE-2015-023615İzleyin
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)
DüşükCVSS 3,5İstismar yokEPSS %2mageia · mageia29 Oca 2015
- CVE-2014-252413İzleyin
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink
DüşükCVSS 3,3İstismar yokEPSS %0gnu · readline20 Ağu 2014
- CVE-2014-35328İzleyin
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service
DüşükCVSS 2,1İstismar yokEPSS %0linux · linux kernel19 Tem 2014
- CVE-2014-81368İzleyin
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when a
DüşükCVSS 2,1İstismar yokEPSS %0mageia · mageia19 Ara 2014