subsonic kayıtları
subsonic üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-295 Improper Certificate Validation1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-9414Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the subsonic · subsonic · CWE-352 | Yüksek8,8 | — | %15,4 | 5 Şub 2018 |
37İzleyin | CVE-2017-9355Kavram kanıtı | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-sidesubsonic · subsonic · CWE-918 | Yüksek7,4 | — | %26,9 | 7 Haz 2017 |
36İzleyin | CVE-2017-9413Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the autsubsonic · subsonic · CWE-352 | Yüksek8,8 | — | %1,8 | 25 Tem 2017 |
32İzleyin | CVE-2018-20228İstismar yok | Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.subsonic · subsonic · CWE-352 | Yüksek8,0 | — | %0,4 | 19 Ara 2018 |
31İzleyin | CVE-2017-9415Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack thsubsonic · subsonic · CWE-352 | Yüksek7,5 | — | %2,5 | 21 Tem 2017 |
26İzleyin | CVE-2018-6014İstismar yok | Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user insubsonic · subsonic · CWE-200 | Orta6,5 | — | %1,2 | 22 Oca 2018 |
24İzleyin | CVE-2018-9282İstismar yok | An XSS issue was discovered in Subsonic Media Server 6.1.1.subsonic · subsonic · CWE-79 | Orta6,1 | — | %0,7 | 21 Eyl 2018 |
24İzleyin | CVE-2018-14688İstismar yok | An issue was discovered in Subsonic 6.1.1.subsonic · subsonic · CWE-79 | Orta6,1 | — | %0,7 | 21 Eyl 2018 |
24İzleyin | CVE-2018-14689İstismar yok | An issue was discovered in Subsonic 6.1.1.subsonic · subsonic · CWE-79 | Orta6,1 | — | %0,7 | 21 Eyl 2018 |
24İzleyin | CVE-2018-14690İstismar yok | An issue was discovered in Subsonic 6.1.1.subsonic · subsonic · CWE-79 | Orta6,1 | — | %0,7 | 21 Eyl 2018 |
24İzleyin | CVE-2018-14691İstismar yok | An issue was discovered in Subsonic 6.1.1.subsonic · subsonic · CWE-79 | Orta6,1 | — | %0,7 | 21 Eyl 2018 |
23İzleyin | CVE-2018-15898İstismar yok | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might subsonic · music streamer · CWE-295 | Orta5,9 | — | %0,9 | 11 Eyl 2018 |
- CVE-2017-941440Planlayın
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the
YüksekCVSS 8,8Kavram kanıtıEPSS %15subsonic · subsonic5 Şub 2018
- CVE-2017-935537İzleyin
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side
YüksekCVSS 7,4Kavram kanıtıEPSS %27subsonic · subsonic7 Haz 2017
- CVE-2017-941336İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the aut
YüksekCVSS 8,8Kavram kanıtıEPSS %2subsonic · subsonic25 Tem 2017
- CVE-2018-2022832İzleyin
Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
YüksekCVSS 8,0İstismar yokEPSS %0subsonic · subsonic19 Ara 2018
- CVE-2017-941531İzleyin
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack th
YüksekCVSS 7,5Kavram kanıtıEPSS %2subsonic · subsonic21 Tem 2017
- CVE-2018-601426İzleyin
Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user in
OrtaCVSS 6,5İstismar yokEPSS %1subsonic · subsonic22 Oca 2018
- CVE-2018-928224İzleyin
An XSS issue was discovered in Subsonic Media Server 6.1.1.
OrtaCVSS 6,1İstismar yokEPSS %1subsonic · subsonic21 Eyl 2018
- CVE-2018-1468824İzleyin
An issue was discovered in Subsonic 6.1.1.
OrtaCVSS 6,1İstismar yokEPSS %1subsonic · subsonic21 Eyl 2018
- CVE-2018-1468924İzleyin
An issue was discovered in Subsonic 6.1.1.
OrtaCVSS 6,1İstismar yokEPSS %1subsonic · subsonic21 Eyl 2018
- CVE-2018-1469024İzleyin
An issue was discovered in Subsonic 6.1.1.
OrtaCVSS 6,1İstismar yokEPSS %1subsonic · subsonic21 Eyl 2018
- CVE-2018-1469124İzleyin
An issue was discovered in Subsonic 6.1.1.
OrtaCVSS 6,1İstismar yokEPSS %1subsonic · subsonic21 Eyl 2018
- CVE-2018-1589823İzleyin
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might
OrtaCVSS 5,9İstismar yokEPSS %1subsonic · music streamer11 Eyl 2018