shadow project kayıtları
shadow project üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-190 Integer Overflow or Wraparound1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-12424İstismar yok | In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors.shadow project · shadow · CWE-119 | Kritik9,8 | — | %2,7 | 4 Ağu 2017 |
31İzleyin | CVE-2019-19882İstismar yok | shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access becauseshadow project · shadow · CWE-732 | Yüksek7,8 | — | %0,5 | 18 Ara 2019 |
31İzleyin | CVE-2016-6252İstismar yok | Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.shadow project · shadow · CWE-190 | Yüksek7,8 | — | %0,4 | 17 Şub 2017 |
21İzleyin | CVE-2018-7169İstismar yok | An issue was discovered in shadow 4.5.shadow project · shadow · CWE-732 | Orta5,3 | — | %1,6 | 15 Şub 2018 |
13İzleyin | CVE-2023-29383İstismar yok | In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger).shadow project · shadow · CWE-74 | Düşük3,3 | — | %0,4 | 14 Nis 2023 |
- CVE-2017-1242440Planlayın
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors.
KritikCVSS 9,8İstismar yokEPSS %3shadow project · shadow4 Ağu 2017
- CVE-2019-1988231İzleyin
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because
YüksekCVSS 7,8İstismar yokEPSS %1shadow project · shadow18 Ara 2019
- CVE-2016-625231İzleyin
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
YüksekCVSS 7,8İstismar yokEPSS %0shadow project · shadow17 Şub 2017
- CVE-2018-716921İzleyin
An issue was discovered in shadow 4.5.
OrtaCVSS 5,3İstismar yokEPSS %2shadow project · shadow15 Şub 2018
- CVE-2023-2938313İzleyin
In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger).
DüşükCVSS 3,3İstismar yokEPSS %0shadow project · shadow14 Nis 2023