rpath kayıtları
rpath üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %63,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-399 Resource Management Errors2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2006-6235İstismar yok | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Kritik10,0 | — | %5,9 | 7 Ara 2006 |
36İzleyin | CVE-2007-1351İstismar yok | Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allx.org · libxfont · CWE-189 | Yüksek8,5 | — | %5,6 | 5 Nis 2007 |
32İzleyin | CVE-2007-5962Kavram kanıtı | Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresighredhat · enterprise linux · CWE-399 | Yüksek7,1 | — | %12,1 | 22 May 2008 |
31İzleyin | CVE-2008-0411Kavram kanıtı | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrghostscript · ghostscript · CWE-119 | Orta6,8 | — | %14,5 | 28 Şub 2008 |
31İzleyin | CVE-2007-5116İstismar yok | Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackerdebian · debian linux · CWE-119 | Yüksek7,5 | — | %4,8 | 7 Kas 2007 |
31İzleyin | CVE-2008-5516İstismar yok | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | Yüksek7,5 | — | %4,4 | 20 Oca 2009 |
28İzleyin | CVE-2007-3106İstismar yok | lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service andlibvorbis · libvorbis · CWE-399 | Orta6,8 | — | %3,1 | 26 Tem 2007 |
28İzleyin | CVE-2007-4131İstismar yok | Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrgnu · tar | Orta6,8 | — | %2,7 | 24 Ağu 2007 |
28İzleyin | CVE-2008-1078İstismar yok | expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files vgentoo · linux · CWE-59 | Yüksek7,2 | — | %0,5 | 28 Şub 2008 |
28İzleyin | CVE-2007-0536İstismar yok | The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissirpath · rpath linux | Yüksek7,2 | — | %0,4 | 26 Oca 2007 |
27İzleyin | CVE-2007-4029İstismar yok | libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalilibvorbis · libvorbis | Orta6,8 | — | %1,7 | 26 Tem 2007 |
27İzleyin | CVE-2007-5194İstismar yok | The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device nrpath · rmake · CWE-264 | Orta6,9 | — | %0,3 | 4 Eki 2007 |
27İzleyin | CVE-2008-4832İstismar yok | rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directorrpath · initscripts · CWE-59 | Orta6,9 | — | %0,3 | 17 Kas 2008 |
26İzleyin | CVE-2008-2139İstismar yok | The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session,rpath · appliance platform agent · CWE-264 | Orta6,5 | — | %0,4 | 12 May 2008 |
21İzleyin | CVE-2008-3139İstismar yok | The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via uwireshark · wireshark · CWE-200 | Orta5,0 | — | %2,9 | 10 Tem 2008 |
21İzleyin | CVE-2008-3138İstismar yok | The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of serwireshark · wireshark · CWE-200 | Orta5,0 | — | %2,0 | 10 Tem 2008 |
19İzleyin | CVE-2007-5686İstismar yok | initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information rpath · rpath linux · CWE-264 | Orta4,9 | — | %0,9 | 28 Eki 2007 |
15İzleyin | CVE-2007-1352İstismar yok | Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary x.org · libxfont | Düşük3,8 | — | %1,5 | 5 Nis 2007 |
10İzleyin | CVE-2008-2140İstismar yok | Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to rerpath · appliance platform agent · CWE-352 | Düşük2,6 | — | %0,4 | 12 May 2008 |
- CVE-2006-623542Planlayın
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
KritikCVSS 10,0İstismar yokEPSS %6gnu · privacy guard7 Ara 2006
- CVE-2007-135136İzleyin
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier all
YüksekCVSS 8,5İstismar yokEPSS %6x.org · libxfont5 Nis 2007
- CVE-2007-596232İzleyin
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresigh
YüksekCVSS 7,1Kavram kanıtıEPSS %12redhat · enterprise linux22 May 2008
- CVE-2008-041131İzleyin
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitr
OrtaCVSS 6,8Kavram kanıtıEPSS %15ghostscript · ghostscript28 Şub 2008
- CVE-2007-511631İzleyin
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker
YüksekCVSS 7,5İstismar yokEPSS %5debian · debian linux7 Kas 2007
- CVE-2008-551631İzleyin
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
YüksekCVSS 7,5İstismar yokEPSS %4git · git20 Oca 2009
- CVE-2007-310628İzleyin
lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and
OrtaCVSS 6,8İstismar yokEPSS %3libvorbis · libvorbis26 Tem 2007
- CVE-2007-413128İzleyin
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwr
OrtaCVSS 6,8İstismar yokEPSS %3gnu · tar24 Ağu 2007
- CVE-2008-107828İzleyin
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files v
YüksekCVSS 7,2İstismar yokEPSS %1gentoo · linux28 Şub 2008
- CVE-2007-053628İzleyin
The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissi
YüksekCVSS 7,2İstismar yokEPSS %0rpath · rpath linux26 Oca 2007
- CVE-2007-402927İzleyin
libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invali
OrtaCVSS 6,8İstismar yokEPSS %2libvorbis · libvorbis26 Tem 2007
- CVE-2007-519427İzleyin
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device n
OrtaCVSS 6,9İstismar yokEPSS %0rpath · rmake4 Eki 2007
- CVE-2008-483227İzleyin
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a director
OrtaCVSS 6,9İstismar yokEPSS %0rpath · initscripts17 Kas 2008
- CVE-2008-213926İzleyin
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session,
OrtaCVSS 6,5İstismar yokEPSS %0rpath · appliance platform agent12 May 2008
- CVE-2008-313921İzleyin
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via u
OrtaCVSS 5,0İstismar yokEPSS %3wireshark · wireshark10 Tem 2008
- CVE-2008-313821İzleyin
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of ser
OrtaCVSS 5,0İstismar yokEPSS %2wireshark · wireshark10 Tem 2008
- CVE-2007-568619İzleyin
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information
OrtaCVSS 4,9İstismar yokEPSS %1rpath · rpath linux28 Eki 2007
- CVE-2007-135215İzleyin
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary
DüşükCVSS 3,8İstismar yokEPSS %2x.org · libxfont5 Nis 2007
- CVE-2008-214010İzleyin
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to re
DüşükCVSS 2,6İstismar yokEPSS %0rpath · appliance platform agent12 May 2008