w3c kayıtları
w3c üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %9,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2008-5282Kavram kanıtı | Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with aw3c · amaya web browser · CWE-119 | Kritik10,0 | — | %17,6 | 28 Kas 2008 |
41Planlayın | CVE-2008-6005İstismar yok | Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, migw3c · amaya web browser · CWE-119 | Kritik10,0 | — | %4,6 | 28 Oca 2009 |
35İzleyin | CVE-2006-1900Kavram kanıtı | Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remotew3c · amaya | Yüksek7,6 | — | %16,5 | 20 Nis 2006 |
31İzleyin | CVE-2000-0079İstismar yok | The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.w3c · cern httpd | Yüksek7,5 | — | %2,0 | 18 Oca 2000 |
29İzleyin | CVE-2024-34581İstismar yok | The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is CWE-918 | Yüksek7,3 | — | %0,2 | 26 Haz 2024 |
28İzleyin | CVE-2002-1053İstismar yok | Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a Uw3c · jigsaw | Orta6,8 | — | %2,1 | 4 Eki 2002 |
25İzleyin | CVE-2004-2274İstismar yok | Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.w3c · jigsaw | Orta6,4 | — | %1,3 | 31 Ara 2004 |
21İzleyin | CVE-2002-1052İstismar yok | Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using tw3c · jigsaw | Orta5,0 | — | %2,8 | 4 Eki 2002 |
21İzleyin | CVE-2020-4070İstismar yok | Cross-site Scripting in CSS Validatorw3c · css validator · CWE-79 | Orta5,4 | — | %0,6 | 22 Haz 2020 |
18İzleyin | CVE-2002-1445Kavram kanıtı | Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-ew3c · cern httpd | Orta4,3 | — | %3,9 | 12 Ağu 2002 |
18İzleyin | CVE-2005-3183İstismar yok | The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation w3c · libwww · CWE-20 | Orta4,3 | — | %2,1 | 12 Eki 2005 |
- CVE-2008-528245Planlayın
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a
KritikCVSS 10,0Kavram kanıtıEPSS %18w3c · amaya web browser28 Kas 2008
- CVE-2008-600541Planlayın
Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, mig
KritikCVSS 10,0İstismar yokEPSS %5w3c · amaya web browser28 Oca 2009
- CVE-2006-190035İzleyin
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote
YüksekCVSS 7,6Kavram kanıtıEPSS %17w3c · amaya20 Nis 2006
- CVE-2000-007931İzleyin
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.
YüksekCVSS 7,5İstismar yokEPSS %2w3c · cern httpd18 Oca 2000
- CVE-2024-3458129İzleyin
The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is
YüksekCVSS 7,3İstismar yokEPSS %026 Haz 2024
- CVE-2002-105328İzleyin
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a U
OrtaCVSS 6,8İstismar yokEPSS %2w3c · jigsaw4 Eki 2002
- CVE-2004-227425İzleyin
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.
OrtaCVSS 6,4İstismar yokEPSS %1w3c · jigsaw31 Ara 2004
- CVE-2002-105221İzleyin
Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using t
OrtaCVSS 5,0İstismar yokEPSS %3w3c · jigsaw4 Eki 2002
- CVE-2020-407021İzleyin
Cross-site Scripting in CSS Validator
OrtaCVSS 5,4İstismar yokEPSS %1w3c · css validator22 Haz 2020
- CVE-2002-144518İzleyin
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-e
OrtaCVSS 4,3Kavram kanıtıEPSS %4w3c · cern httpd12 Ağu 2002
- CVE-2005-318318İzleyin
The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation
OrtaCVSS 4,3İstismar yokEPSS %2w3c · libwww12 Eki 2005