pgp kayıtları
pgp üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %4,3
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-459 Incomplete Cleanup2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2001-1320Silahlaştırılmış | Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via expgp · keyserver | Yüksek7,5 | — | %68,3 | 16 Tem 2001 |
41Planlayın | CVE-2001-1252İstismar yok | Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs tpgp · keyserver | Kritik10,0 | — | %3,2 | 28 Eyl 2001 |
38İzleyin | CVE-2010-3397İstismar yok | Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local userpgp · desktop | Kritik9,3 | — | %4,2 | 15 Eyl 2010 |
32İzleyin | CVE-2001-1456İstismar yok | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitramcafee · webshield smtp · CWE-119 | Yüksek7,5 | — | %5,7 | 4 Eyl 2001 |
31İzleyin | CVE-2002-0850İstismar yok | Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long fpgp · corporate desktop | Yüksek7,5 | — | %3,2 | 4 Eki 2002 |
31İzleyin | CVE-2002-0685İstismar yok | Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0pgp · desktop security | Yüksek7,5 | — | %2,6 | 23 Tem 2002 |
31İzleyin | CVE-2002-2069İstismar yok | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recpgp · personal privacy · CWE-459 | Yüksek7,5 | — | %2,1 | 31 Ara 2002 |
30İzleyin | CVE-2007-0603İstismar yok | PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpspgp · corporate desktop | Yüksek7,1 | — | %5,2 | 30 Oca 2007 |
30İzleyin | CVE-2001-1016İstismar yok | PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly pgp · corporate desktop | Yüksek7,5 | — | %1,4 | 4 Eyl 2001 |
28İzleyin | CVE-2009-0681İstismar yok | PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) causpgp · desktop · CWE-20 | Yüksek7,2 | — | %0,4 | 15 Nis 2009 |
22İzleyin | CVE-2002-0788İstismar yok | An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartextpgp · corporate desktop · CWE-459 | Orta5,5 | — | %0,4 | 12 Ağu 2002 |
22İzleyin | CVE-2002-1696İstismar yok | Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically depgp · personal privacy · CWE-312 | Orta5,5 | — | %0,3 | 31 Ara 2002 |
20İzleyin | CVE-2000-0678İstismar yok | PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificatpgp · pgp | Orta5,0 | — | %1,5 | 20 Eki 2000 |
20İzleyin | CVE-2000-0543İstismar yok | The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not pgp · certificate server | Orta5,0 | — | %1,1 | 14 Haz 2000 |
19İzleyin | CVE-2008-5731Kavram kanıtı | The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause pgp · desktop · CWE-399 | Orta4,9 | — | %0,9 | 26 Ara 2008 |
18İzleyin | CVE-2001-0381İstismar yok | The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters tpgp · openpgp | Orta4,6 | — | %0,4 | 27 Haz 2001 |
18İzleyin | CVE-2001-0435İstismar yok | The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while pgp · pgp | Orta4,6 | — | %0,3 | 2 Tem 2001 |
17İzleyin | CVE-2010-3618İstismar yok | PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" funcpgp · desktop for windows · CWE-310 | Orta4,3 | — | %1,6 | 22 Kas 2010 |
14İzleyin | CVE-2000-0802İstismar yok | The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain accesspgp · personal privacy | Düşük3,6 | — | %0,3 | 20 Eki 2000 |
8İzleyin | CVE-2001-0265Kavram kanıtı | ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored fipgp · pgp | Düşük2,1 | — | %0,7 | 18 Haz 2001 |
8İzleyin | CVE-2005-4151İstismar yok | The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space inpgp · desktop | Düşük2,1 | — | %0,5 | 10 Ara 2005 |
8İzleyin | CVE-2000-0445İstismar yok | The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may propgp · pgp | Düşük2,1 | — | %0,4 | 24 May 2000 |
8İzleyin | CVE-2002-1977İstismar yok | Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackpgp · pgp | Düşük2,1 | — | %0,4 | 31 Ara 2002 |
- CVE-2001-132050Planlayın
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via ex
YüksekCVSS 7,5SilahlaştırılmışEPSS %68pgp · keyserver16 Tem 2001
- CVE-2001-125241Planlayın
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs t
KritikCVSS 10,0İstismar yokEPSS %3pgp · keyserver28 Eyl 2001
- CVE-2010-339738İzleyin
Untrusted search path vulnerability in PGP Desktop 9.9.0 Build 397, 9.10.x, 10.0.0 Build 2732, and probably other versions allows local user
KritikCVSS 9,3İstismar yokEPSS %4pgp · desktop15 Eyl 2010
- CVE-2001-145632İzleyin
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitra
YüksekCVSS 7,5İstismar yokEPSS %6mcafee · webshield smtp4 Eyl 2001
- CVE-2002-085031İzleyin
Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long f
YüksekCVSS 7,5İstismar yokEPSS %3pgp · corporate desktop4 Eki 2002
- CVE-2002-068531İzleyin
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0
YüksekCVSS 7,5İstismar yokEPSS %3pgp · desktop security23 Tem 2002
- CVE-2002-206931İzleyin
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to rec
YüksekCVSS 7,5İstismar yokEPSS %2pgp · personal privacy31 Ara 2002
- CVE-2007-060330İzleyin
PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgps
YüksekCVSS 7,1İstismar yokEPSS %5pgp · corporate desktop30 Oca 2007
- CVE-2001-101630İzleyin
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly
YüksekCVSS 7,5İstismar yokEPSS %1pgp · corporate desktop4 Eyl 2001
- CVE-2009-068128İzleyin
PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) caus
YüksekCVSS 7,2İstismar yokEPSS %0pgp · desktop15 Nis 2009
- CVE-2002-078822İzleyin
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext
OrtaCVSS 5,5İstismar yokEPSS %0pgp · corporate desktop12 Ağu 2002
- CVE-2002-169622İzleyin
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically de
OrtaCVSS 5,5İstismar yokEPSS %0pgp · personal privacy31 Ara 2002
- CVE-2000-067820İzleyin
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificat
OrtaCVSS 5,0İstismar yokEPSS %2pgp · pgp20 Eki 2000
- CVE-2000-054320İzleyin
The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not
OrtaCVSS 5,0İstismar yokEPSS %1pgp · certificate server14 Haz 2000
- CVE-2008-573119İzleyin
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause
OrtaCVSS 4,9Kavram kanıtıEPSS %1pgp · desktop26 Ara 2008
- CVE-2001-038118İzleyin
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters t
OrtaCVSS 4,6İstismar yokEPSS %0pgp · openpgp27 Haz 2001
- CVE-2001-043518İzleyin
The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while
OrtaCVSS 4,6İstismar yokEPSS %0pgp · pgp2 Tem 2001
- CVE-2010-361817İzleyin
PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" func
OrtaCVSS 4,3İstismar yokEPSS %2pgp · desktop for windows22 Kas 2010
- CVE-2000-080214İzleyin
The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access
DüşükCVSS 3,6İstismar yokEPSS %0pgp · personal privacy20 Eki 2000
- CVE-2001-02658İzleyin
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored fi
DüşükCVSS 2,1Kavram kanıtıEPSS %1pgp · pgp18 Haz 2001
- CVE-2005-41518İzleyin
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in
DüşükCVSS 2,1İstismar yokEPSS %0pgp · desktop10 Ara 2005
- CVE-2000-04458İzleyin
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may pro
DüşükCVSS 2,1İstismar yokEPSS %0pgp · pgp24 May 2000
- CVE-2002-19778İzleyin
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attack
DüşükCVSS 2,1İstismar yokEPSS %0pgp · pgp31 Ara 2002