openpkg kayıtları
openpkg üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,7
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %88,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-131 Incorrect Calculation of Buffer Size1
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-203 Observable Discrepancy1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2004-0990Kavram kanıtı | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of sergd graphics library · gdlib | Kritik10,0 | — | %28,3 | 1 Mar 2005 |
47Planlayın | CVE-2004-0333Kavram kanıtı | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Kritik10,0 | — | %24,2 | 23 Kas 2004 |
44Planlayın | CVE-2004-0416Kavram kanıtı | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Kritik10,0 | — | %13,2 | 6 Ağu 2004 |
43Planlayın | CVE-2003-0190Silahlaştırılmış | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, whichopenbsd · openssh · CWE-203 | Orta5,0 | — | %76,8 | 12 May 2003 |
43Planlayın | CVE-2002-0083Kavram kanıtı | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Kritik9,8 | — | %14,7 | 15 Mar 2002 |
43Planlayın | CVE-2004-1065İstismar yok | Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary codphp · php | Kritik10,0 | — | %10,0 | 10 Oca 2005 |
42Planlayın | CVE-2004-1019İstismar yok | The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitphp · php · CWE-20 | Kritik10,0 | — | %8,0 | 10 Oca 2005 |
42Planlayın | CVE-2004-1012İstismar yok | The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Kritik10,0 | — | %6,0 | 10 Oca 2005 |
42Planlayın | CVE-2004-0413İstismar yok | libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allowsubversion · subversion | Kritik10,0 | — | %5,9 | 6 Ağu 2004 |
42Planlayın | CVE-2004-1011İstismar yok | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execcarnegie mellon university · cyrus imap server | Kritik10,0 | — | %5,8 | 10 Oca 2005 |
42Planlayın | CVE-2004-1013İstismar yok | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Kritik10,0 | — | %5,8 | 10 Oca 2005 |
42Planlayın | CVE-2004-0418İstismar yok | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Kritik10,0 | — | %5,7 | 6 Ağu 2004 |
41Planlayın | CVE-2004-0772İstismar yok | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Kritik9,8 | — | %7,0 | 20 Eki 2004 |
41Planlayın | CVE-2004-0414İstismar yok | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator frcvs · cvs | Kritik10,0 | — | %4,0 | 6 Ağu 2004 |
36İzleyin | CVE-2004-0594Kavram kanıtı | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enahp · hp-ux · CWE-367 | Orta5,1 | — | %54,9 | 27 Tem 2004 |
32İzleyin | CVE-2004-0940Kavram kanıtı | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to executeapache · http server · CWE-131 | Yüksek7,8 | — | %4,8 | 9 Şub 2005 |
31İzleyin | CVE-2007-5116İstismar yok | Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackerdebian · debian linux · CWE-119 | Yüksek7,5 | — | %4,8 | 7 Kas 2007 |
31İzleyin | CVE-2005-0373İstismar yok | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | Yüksek7,5 | — | %3,9 | 7 Eki 2004 |
31İzleyin | CVE-2002-0985İstismar yok | Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify cphp · php · CWE-88 | Yüksek7,5 | — | %3,0 | 24 Eyl 2002 |
30İzleyin | CVE-2004-1471Kavram kanıtı | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commicvs · cvs | Yüksek7,1 | — | %7,7 | 31 Ara 2004 |
28İzleyin | CVE-2004-0957İstismar yok | Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), openpkg · openpkg | Orta6,8 | — | %2,4 | 9 Şub 2005 |
25İzleyin | CVE-2004-0918İstismar yok | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a desquid · squid · CWE-399 | Orta5,0 | — | %15,8 | 27 Oca 2005 |
22İzleyin | CVE-2003-0147İstismar yok | OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factopenssl · openssl | Orta5,0 | — | %6,4 | 31 Mar 2003 |
21İzleyin | CVE-2004-0421İstismar yok | The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG libpng · libpng · CWE-125 | Orta5,0 | — | %4,1 | 18 Ağu 2004 |
21İzleyin | CVE-2004-0417İstismar yok | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may cvs · cvs | Orta5,0 | — | %3,1 | 6 Ağu 2004 |
- CVE-2004-099048Planlayın
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of ser
KritikCVSS 10,0Kavram kanıtıEPSS %28gd graphics library · gdlib1 Mar 2005
- CVE-2004-033347Planlayın
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
KritikCVSS 10,0Kavram kanıtıEPSS %24uudeview · uudeview23 Kas 2004
- CVE-2004-041644Planlayın
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
KritikCVSS 10,0Kavram kanıtıEPSS %13cvs · cvs6 Ağu 2004
- CVE-2003-019043Planlayın
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which
OrtaCVSS 5,0SilahlaştırılmışEPSS %77openbsd · openssh12 May 2003
- CVE-2002-008343Planlayın
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
KritikCVSS 9,8Kavram kanıtıEPSS %15immunix · immunix15 Mar 2002
- CVE-2004-106543Planlayın
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary cod
KritikCVSS 10,0İstismar yokEPSS %10php · php10 Oca 2005
- CVE-2004-101942Planlayın
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbit
KritikCVSS 10,0İstismar yokEPSS %8php · php10 Oca 2005
- CVE-2004-101242Planlayın
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod
KritikCVSS 10,0İstismar yokEPSS %6carnegie mellon university · cyrus imap server10 Oca 2005
- CVE-2004-041342Planlayın
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allow
KritikCVSS 10,0İstismar yokEPSS %6subversion · subversion6 Ağu 2004
- CVE-2004-101142Planlayın
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec
KritikCVSS 10,0İstismar yokEPSS %6carnegie mellon university · cyrus imap server10 Oca 2005
- CVE-2004-101342Planlayın
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod
KritikCVSS 10,0İstismar yokEPSS %6carnegie mellon university · cyrus imap server10 Oca 2005
- CVE-2004-041842Planlayın
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
KritikCVSS 10,0İstismar yokEPSS %6cvs · cvs6 Ağu 2004
- CVE-2004-077241Planlayın
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
KritikCVSS 9,8İstismar yokEPSS %7mit · kerberos 520 Eki 2004
- CVE-2004-041441Planlayın
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr
KritikCVSS 10,0İstismar yokEPSS %4cvs · cvs6 Ağu 2004
- CVE-2004-059436İzleyin
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is ena
OrtaCVSS 5,1Kavram kanıtıEPSS %55hp · hp-ux27 Tem 2004
- CVE-2004-094032İzleyin
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute
YüksekCVSS 7,8Kavram kanıtıEPSS %5apache · http server9 Şub 2005
- CVE-2007-511631İzleyin
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker
YüksekCVSS 7,5İstismar yokEPSS %5debian · debian linux7 Kas 2007
- CVE-2005-037331İzleyin
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
YüksekCVSS 7,5İstismar yokEPSS %4cyrus · sasl7 Eki 2004
- CVE-2002-098531İzleyin
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify c
YüksekCVSS 7,5İstismar yokEPSS %3php · php24 Eyl 2002
- CVE-2004-147130İzleyin
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi
YüksekCVSS 7,1Kavram kanıtıEPSS %8cvs · cvs31 Ara 2004
- CVE-2004-095728İzleyin
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore),
OrtaCVSS 6,8İstismar yokEPSS %2openpkg · openpkg9 Şub 2005
- CVE-2004-091825İzleyin
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de
OrtaCVSS 5,0İstismar yokEPSS %16squid · squid27 Oca 2005
- CVE-2003-014722İzleyin
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining fact
OrtaCVSS 5,0İstismar yokEPSS %6openssl · openssl31 Mar 2003
- CVE-2004-042121İzleyin
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG
OrtaCVSS 5,0İstismar yokEPSS %4libpng · libpng18 Ağu 2004
- CVE-2004-041721İzleyin
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may
OrtaCVSS 5,0İstismar yokEPSS %3cvs · cvs6 Ağu 2004