pulseaudio kayıtları
pulseaudio üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-404 Improper Resource Shutdown or Release1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2007-1804Kavram kanıtı | PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_Spulseaudio · pulseaudio | Yüksek7,8 | — | %7,4 | 2 Nis 2007 |
28İzleyin | CVE-2009-1894Kavram kanıtı | Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, pulseaudio · pulseaudio · CWE-362 | Yüksek7,2 | — | %0,7 | 17 Tem 2009 |
28İzleyin | CVE-2008-0008İstismar yok | The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3)pulseaudio · pulseaudio · CWE-20 | Yüksek7,2 | — | %0,6 | 28 Oca 2008 |
27İzleyin | CVE-2009-1299İstismar yok | The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions ofpulseaudio · pulseaudio · CWE-59 | Orta6,9 | — | %0,3 | 18 Mar 2010 |
16İzleyin | CVE-2024-11586İstismar yok | Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.pulseaudio · pulseaudio · CWE-404 | Orta4,0 | — | %0,3 | 22 Kas 2024 |
13İzleyin | CVE-2020-11931İstismar yok | Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloadedpulseaudio · pulseaudio · CWE-284 | Düşük3,3 | — | %0,3 | 15 May 2020 |
11İzleyin | CVE-2014-3970İstismar yok | The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause apulseaudio · pulseaudio | Düşük2,9 | — | %1,5 | 11 Haz 2014 |
- CVE-2007-180433İzleyin
PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_S
YüksekCVSS 7,8Kavram kanıtıEPSS %7pulseaudio · pulseaudio2 Nis 2007
- CVE-2009-189428İzleyin
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link,
YüksekCVSS 7,2Kavram kanıtıEPSS %1pulseaudio · pulseaudio17 Tem 2009
- CVE-2008-000828İzleyin
The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3)
YüksekCVSS 7,2İstismar yokEPSS %1pulseaudio · pulseaudio28 Oca 2008
- CVE-2009-129927İzleyin
The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of
OrtaCVSS 6,9İstismar yokEPSS %0pulseaudio · pulseaudio18 Mar 2010
- CVE-2024-1158616İzleyin
Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.
OrtaCVSS 4,0İstismar yokEPSS %0pulseaudio · pulseaudio22 Kas 2024
- CVE-2020-1193113İzleyin
Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloaded
DüşükCVSS 3,3İstismar yokEPSS %0pulseaudio · pulseaudio15 May 2020
- CVE-2014-397011İzleyin
The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a
DüşükCVSS 2,9İstismar yokEPSS %1pulseaudio · pulseaudio11 Haz 2014