wesnoth kayıtları
wesnoth üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %90
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-399 Resource Management Errors2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2009-0367Kavram kanıtı | The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by usinwesnoth · wesnoth · CWE-264 | Kritik9,3 | — | %10,9 | 4 Mar 2009 |
37İzleyin | CVE-2007-5742İstismar yok | Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attawesnoth · wesnoth · CWE-22 | Kritik9,0 | — | %2,8 | 1 Ara 2007 |
36İzleyin | CVE-2018-1999023İstismar yok | The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can reswesnoth · the battle for wesnoth · CWE-94 | Yüksek8,8 | — | %1,7 | 23 Tem 2018 |
32İzleyin | CVE-2007-3917İstismar yok | The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via awesnoth · wesnoth · CWE-134 | Yüksek7,8 | — | %2,1 | 11 Eki 2007 |
30İzleyin | CVE-2007-6201İstismar yok | Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via awesnoth · wesnoth | Yüksek7,5 | — | %1,5 | 1 Ara 2007 |
21İzleyin | CVE-2015-0844İstismar yok | The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crwesnoth · battle for wesnoth · CWE-200 | Orta5,0 | — | %2,3 | 14 Nis 2015 |
21İzleyin | CVE-2009-0878İstismar yok | The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memwesnoth · wesnoth · CWE-399 | Orta5,0 | — | %1,8 | 12 Mar 2009 |
18İzleyin | CVE-2009-0366İstismar yok | The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service viwesnoth · wesnoth · CWE-399 | Orta4,3 | — | %2,0 | 12 Mar 2009 |
18İzleyin | CVE-2015-5069İstismar yok | The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnothwesnoth · battle for wesnoth · CWE-200 | Orta4,3 | — | %1,7 | 26 Eyl 2017 |
12İzleyin | CVE-2015-5070İstismar yok | The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnothwesnoth · battle for wesnoth · CWE-200 | Düşük3,1 | — | %1,4 | 26 Eyl 2017 |
- CVE-2009-036740Planlayın
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by usin
KritikCVSS 9,3Kavram kanıtıEPSS %11wesnoth · wesnoth4 Mar 2009
- CVE-2007-574237İzleyin
Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote atta
KritikCVSS 9,0İstismar yokEPSS %3wesnoth · wesnoth1 Ara 2007
- CVE-2018-199902336İzleyin
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can res
YüksekCVSS 8,8İstismar yokEPSS %2wesnoth · the battle for wesnoth23 Tem 2018
- CVE-2007-391732İzleyin
The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a
YüksekCVSS 7,8İstismar yokEPSS %2wesnoth · wesnoth11 Eki 2007
- CVE-2007-620130İzleyin
Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via a
YüksekCVSS 7,5İstismar yokEPSS %1wesnoth · wesnoth1 Ara 2007
- CVE-2015-084421İzleyin
The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a cr
OrtaCVSS 5,0İstismar yokEPSS %2wesnoth · battle for wesnoth14 Nis 2015
- CVE-2009-087821İzleyin
The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (mem
OrtaCVSS 5,0İstismar yokEPSS %2wesnoth · wesnoth12 Mar 2009
- CVE-2009-036618İzleyin
The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service vi
OrtaCVSS 4,3İstismar yokEPSS %2wesnoth · wesnoth12 Mar 2009
- CVE-2015-506918İzleyin
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth
OrtaCVSS 4,3İstismar yokEPSS %2wesnoth · battle for wesnoth26 Eyl 2017
- CVE-2015-507012İzleyin
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth
DüşükCVSS 3,1İstismar yokEPSS %1wesnoth · battle for wesnoth26 Eyl 2017