sourceforge kayıtları
sourceforge üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %15,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-16 Configuration1
- CWE-189 Numeric Errors1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2005-4837İstismar yok | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allownet-snmp · net-snmp · CWE-16 | Kritik10,0 | — | %9,7 | 31 Ara 2005 |
37İzleyin | CVE-2008-2503İstismar yok | Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.sourceforge · emule x-ray · CWE-119 | Kritik9,3 | — | %1,4 | 29 May 2008 |
31İzleyin | CVE-2008-2298Kavram kanıtı | Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.sourceforge · web slider · CWE-287 | Yüksek7,5 | — | %2,8 | 18 May 2008 |
31İzleyin | CVE-2001-0234İstismar yok | NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parametersourceforge · newsdaemon | Yüksek7,5 | — | %1,8 | 3 May 2001 |
28İzleyin | CVE-2007-1466İstismar yok | Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows sourceforge · wordperfect document importer-exporter · CWE-189 | Orta6,8 | — | %3,4 | 16 Mar 2007 |
27İzleyin | CVE-2007-1135İstismar yok | Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1)sourceforge · webmplayer | Orta6,8 | — | %1,1 | 2 Mar 2007 |
27İzleyin | CVE-2007-1572Kavram kanıtı | SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the sourceforge · jgbbs | Orta6,8 | — | %0,8 | 21 Mar 2007 |
25İzleyin | CVE-2007-6640İstismar yok | Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attacsourceforge · creammonkey · CWE-264 | Orta6,4 | — | %1,2 | 3 Oca 2008 |
24İzleyin | CVE-2008-0501Kavram kanıtı | Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a ..sourceforge · phpmyclub · CWE-22 | Orta5,8 | — | %1,9 | 30 Oca 2008 |
20İzleyin | CVE-2007-1137İstismar yok | putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmaisourceforge · putmail | Orta5,0 | — | %0,9 | 2 Mar 2007 |
17İzleyin | CVE-2002-2362Kavram kanıtı | Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML sourceforge · mymarket · CWE-79 | Orta4,3 | — | %1,6 | 31 Ara 2002 |
17İzleyin | CVE-2008-6161İstismar yok | Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTsourceforge · wow raid manager · CWE-79 | Orta4,3 | — | %1,0 | 18 Şub 2009 |
17İzleyin | CVE-2002-2364İstismar yok | Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a sourceforge · php ticket · CWE-79 | Orta4,3 | — | %0,8 | 31 Ara 2002 |
- CVE-2005-483743Planlayın
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allow
KritikCVSS 10,0İstismar yokEPSS %10net-snmp · net-snmp31 Ara 2005
- CVE-2008-250337İzleyin
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.
KritikCVSS 9,3İstismar yokEPSS %1sourceforge · emule x-ray29 May 2008
- CVE-2008-229831İzleyin
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
YüksekCVSS 7,5Kavram kanıtıEPSS %3sourceforge · web slider18 May 2008
- CVE-2001-023431İzleyin
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter
YüksekCVSS 7,5İstismar yokEPSS %2sourceforge · newsdaemon3 May 2001
- CVE-2007-146628İzleyin
Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows
OrtaCVSS 6,8İstismar yokEPSS %3sourceforge · wordperfect document importer-exporter16 Mar 2007
- CVE-2007-113527İzleyin
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1)
OrtaCVSS 6,8İstismar yokEPSS %1sourceforge · webmplayer2 Mar 2007
- CVE-2007-157227İzleyin
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the
OrtaCVSS 6,8Kavram kanıtıEPSS %1sourceforge · jgbbs21 Mar 2007
- CVE-2007-664025İzleyin
Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attac
OrtaCVSS 6,4İstismar yokEPSS %1sourceforge · creammonkey3 Oca 2008
- CVE-2008-050124İzleyin
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a ..
OrtaCVSS 5,8Kavram kanıtıEPSS %2sourceforge · phpmyclub30 Oca 2008
- CVE-2007-113720İzleyin
putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmai
OrtaCVSS 5,0İstismar yokEPSS %1sourceforge · putmail2 Mar 2007
- CVE-2002-236217İzleyin
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %2sourceforge · mymarket31 Ara 2002
- CVE-2008-616117İzleyin
Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HT
OrtaCVSS 4,3İstismar yokEPSS %1sourceforge · wow raid manager18 Şub 2009
- CVE-2002-236417İzleyin
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a
OrtaCVSS 4,3İstismar yokEPSS %1sourceforge · php ticket31 Ara 2002