systemtap kayıtları
systemtap üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %8,3
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-189 Numeric Errors3
- CWE-20 Improper Input Validation3
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2009-4273Kavram kanıtı | stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line argusystemtap · systemtap · CWE-94 | Kritik10,0 | — | %17,7 | 26 Oca 2010 |
31İzleyin | CVE-2010-0412İstismar yok | stap-server in SystemTap 1.1 does not properly restrict the value of the -B (aka BUILD) option, which allows attackers to have an unspecifiesystemtap · systemtap | Yüksek7,5 | — | %1,7 | 24 Şub 2010 |
30İzleyin | CVE-2010-4170Silahlaştırılmış | The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gaisystemtap · systemtap · CWE-264 | Yüksek7,2 | — | %5,3 | 7 Ara 2010 |
25İzleyin | CVE-2009-0784İstismar yok | Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTasystemtap · systemtap · CWE-362 | Orta6,3 | — | %0,3 | 25 Mar 2009 |
21İzleyin | CVE-2012-0875İstismar yok | SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information frosystemtap · systemtap · CWE-264 | Orta5,4 | — | %0,4 | 4 Şub 2014 |
19İzleyin | CVE-2010-0411Kavram kanıtı | Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allsystemtap · systemtap · CWE-189 | Orta4,9 | — | %0,9 | 8 Şub 2010 |
17İzleyin | CVE-2011-2502İstismar yok | runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a mosystemtap · systemtap · CWE-20 | Orta4,4 | — | %0,5 | 26 Tem 2012 |
14İzleyin | CVE-2011-2503İstismar yok | The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not propesystemtap · systemtap · CWE-20 | Düşük3,7 | — | %0,4 | 26 Tem 2012 |
8İzleyin | CVE-2010-4171İstismar yok | The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local usesystemtap · systemtap · CWE-20 | Düşük2,1 | — | %0,4 | 7 Ara 2010 |
7İzleyin | CVE-2009-2911İstismar yok | SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause systemtap · systemtap · CWE-264 | Düşük1,9 | — | %0,5 | 22 Eki 2009 |
4İzleyin | CVE-2011-1781İstismar yok | SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOsystemtap · systemtap · CWE-189 | Düşük1,2 | — | %0,3 | 29 Ağu 2011 |
4İzleyin | CVE-2011-1769İstismar yok | SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero systemtap · systemtap · CWE-189 | Düşük1,2 | — | %0,3 | 29 Ağu 2011 |
- CVE-2009-427345Planlayın
stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line argu
KritikCVSS 10,0Kavram kanıtıEPSS %18systemtap · systemtap26 Oca 2010
- CVE-2010-041231İzleyin
stap-server in SystemTap 1.1 does not properly restrict the value of the -B (aka BUILD) option, which allows attackers to have an unspecifie
YüksekCVSS 7,5İstismar yokEPSS %2systemtap · systemtap24 Şub 2010
- CVE-2010-417030İzleyin
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gai
YüksekCVSS 7,2SilahlaştırılmışEPSS %5systemtap · systemtap7 Ara 2010
- CVE-2009-078425İzleyin
Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTa
OrtaCVSS 6,3İstismar yokEPSS %0systemtap · systemtap25 Mar 2009
- CVE-2012-087521İzleyin
SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information fro
OrtaCVSS 5,4İstismar yokEPSS %0systemtap · systemtap4 Şub 2014
- CVE-2010-041119İzleyin
Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 all
OrtaCVSS 4,9Kavram kanıtıEPSS %1systemtap · systemtap8 Şub 2010
- CVE-2011-250217İzleyin
runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a mo
OrtaCVSS 4,4İstismar yokEPSS %1systemtap · systemtap26 Tem 2012
- CVE-2011-250314İzleyin
The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not prope
DüşükCVSS 3,7İstismar yokEPSS %0systemtap · systemtap26 Tem 2012
- CVE-2010-41718İzleyin
The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local use
DüşükCVSS 2,1İstismar yokEPSS %0systemtap · systemtap7 Ara 2010
- CVE-2009-29117İzleyin
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause
DüşükCVSS 1,9İstismar yokEPSS %0systemtap · systemtap22 Eki 2009
- CVE-2011-17814İzleyin
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OO
DüşükCVSS 1,2İstismar yokEPSS %0systemtap · systemtap29 Ağu 2011
- CVE-2011-17694İzleyin
SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero
DüşükCVSS 1,2İstismar yokEPSS %0systemtap · systemtap29 Ağu 2011