squareup kayıtları
squareup üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %66,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-295 Improper Certificate Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-611 Improper Restriction of XML External Entity Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2015-8969İstismar yok | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.squareup · git-fastclone · CWE-77 | Kritik9,8 | — | %4,8 | 3 Kas 2016 |
39İzleyin | CVE-2020-36645İstismar yok | square squalor sql injectionsquareup · squalor · CWE-89 | Kritik9,8 | — | %0,7 | 7 Oca 2023 |
37İzleyin | CVE-2015-8968İstismar yok | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.squareup · git-fastclone · CWE-77 | Yüksek8,8 | — | %5,2 | 3 Kas 2016 |
37İzleyin | CVE-2018-1000844Kavram kanıtı | Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabilsquareup · retrofit · CWE-611 | Kritik9,1 | — | %2,2 | 20 Ara 2018 |
31İzleyin | CVE-2018-1000850Kavram kanıtı | Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder csquareup · retrofit · CWE-22 | Yüksek7,5 | — | %4,0 | 20 Ara 2018 |
30İzleyin | CVE-2023-3635Kavram kanıtı | Okio GzipSource unhandled exception Denial of Servicesquareup · okio · CWE-195 | Yüksek7,5 | — | %1,3 | 12 Tem 2023 |
30İzleyin | CVE-2026-45799İstismar yok | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding servicesquareup · wire · CWE-129 | Yüksek7,5 | — | %0,7 | 17 Tem 2026 |
24İzleyin | CVE-2018-20200İstismar yok | CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext squareup · okhttp · CWE-295 | Orta5,9 | — | %2,5 | 18 Nis 2019 |
24İzleyin | CVE-2016-2402Kavram kanıtı | OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain witsquareup · okhttp · CWE-295 | Orta5,9 | — | %2,2 | 30 Oca 2017 |
23İzleyin | CVE-2023-3782İstismar yok | DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb squareup · okhttp-brotli · CWE-400 | Orta5,9 | — | %0,7 | 19 Tem 2023 |
22İzleyin | CVE-2023-0833İstismar yok | Red hat a-mq streams: component version with information disclosure flawsquareup · okhttp · CWE-209 | Orta5,5 | — | %0,4 | 27 Eyl 2023 |
13İzleyin | CVE-2021-23331İstismar yok | Insecure Temporary Filesquareup · connect java software development kit | Düşük3,3 | — | %0,3 | 3 Şub 2021 |
- CVE-2015-896940Planlayın
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.
KritikCVSS 9,8İstismar yokEPSS %5squareup · git-fastclone3 Kas 2016
- CVE-2020-3664539İzleyin
square squalor sql injection
KritikCVSS 9,8İstismar yokEPSS %1squareup · squalor7 Oca 2023
- CVE-2015-896837İzleyin
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.
YüksekCVSS 8,8İstismar yokEPSS %5squareup · git-fastclone3 Kas 2016
- CVE-2018-100084437İzleyin
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabil
KritikCVSS 9,1Kavram kanıtıEPSS %2squareup · retrofit20 Ara 2018
- CVE-2018-100085031İzleyin
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder c
YüksekCVSS 7,5Kavram kanıtıEPSS %4squareup · retrofit20 Ara 2018
- CVE-2023-363530İzleyin
Okio GzipSource unhandled exception Denial of Service
YüksekCVSS 7,5Kavram kanıtıEPSS %1squareup · okio12 Tem 2023
- CVE-2026-4579930İzleyin
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
YüksekCVSS 7,5İstismar yokEPSS %1squareup · wire17 Tem 2026
- CVE-2018-2020024İzleyin
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext
OrtaCVSS 5,9İstismar yokEPSS %2squareup · okhttp18 Nis 2019
- CVE-2016-240224İzleyin
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain wit
OrtaCVSS 5,9Kavram kanıtıEPSS %2squareup · okhttp30 Oca 2017
- CVE-2023-378223İzleyin
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb
OrtaCVSS 5,9İstismar yokEPSS %1squareup · okhttp-brotli19 Tem 2023
- CVE-2023-083322İzleyin
Red hat a-mq streams: component version with information disclosure flaw
OrtaCVSS 5,5İstismar yokEPSS %0squareup · okhttp27 Eyl 2023
- CVE-2021-2333113İzleyin
Insecure Temporary File
DüşükCVSS 3,3İstismar yokEPSS %0squareup · connect java software development kit3 Şub 2021