zsh kayıtları
zsh üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-189 Numeric Errors1
- CWE-121 Stack-based Buffer Overflow1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-18206İstismar yok | In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.zsh · zsh · CWE-119 | Kritik9,8 | — | %3,1 | 27 Şub 2018 |
40Planlayın | CVE-2018-13259İstismar yok | An issue was discovered in zsh before 5.6.zsh · zsh · CWE-20 | Kritik9,8 | — | %2,7 | 5 Eyl 2018 |
40Planlayın | CVE-2014-10071İstismar yok | In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.zsh · zsh · CWE-119 | Kritik9,8 | — | %2,7 | 27 Şub 2018 |
40Planlayın | CVE-2018-7548İstismar yok | In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.zsh · zsh · CWE-476 | Kritik9,8 | — | %2,5 | 27 Şub 2018 |
40Planlayın | CVE-2018-0502İstismar yok | An issue was discovered in zsh before 5.6.zsh · zsh · CWE-20 | Kritik9,8 | — | %2,5 | 5 Eyl 2018 |
40Planlayın | CVE-2016-10714İstismar yok | In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.zsh · zsh · CWE-189 | Kritik9,8 | — | %2,1 | 27 Şub 2018 |
32İzleyin | CVE-2021-45444İstismar yok | In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F arguzsh · zsh | Yüksek7,8 | — | %2,0 | 14 Şub 2022 |
31İzleyin | CVE-2018-7549İstismar yok | In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.zsh · zsh · CWE-20 | Yüksek7,5 | — | %2,6 | 27 Şub 2018 |
31İzleyin | CVE-2018-1083İstismar yok | Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality.zsh · zsh · CWE-120 | Yüksek7,8 | — | %0,6 | 28 Mar 2018 |
31İzleyin | CVE-2018-1100İstismar yok | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function.zsh · zsh · CWE-120 | Yüksek7,8 | — | %0,5 | 11 Nis 2018 |
31İzleyin | CVE-2019-20044İstismar yok | In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.zsh · zsh · CWE-273 | Yüksek7,8 | — | %0,5 | 24 Şub 2020 |
22İzleyin | CVE-2018-1071İstismar yok | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function.zsh · zsh · CWE-121 | Orta5,5 | — | %0,4 | 9 Mar 2018 |
18İzleyin | CVE-2007-6209İstismar yok | Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.zsh · zsh · CWE-264 | Orta4,6 | — | %0,3 | 3 Ara 2007 |
- CVE-2017-1820640Planlayın
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
KritikCVSS 9,8İstismar yokEPSS %3zsh · zsh27 Şub 2018
- CVE-2018-1325940Planlayın
An issue was discovered in zsh before 5.6.
KritikCVSS 9,8İstismar yokEPSS %3zsh · zsh5 Eyl 2018
- CVE-2014-1007140Planlayın
In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
KritikCVSS 9,8İstismar yokEPSS %3zsh · zsh27 Şub 2018
- CVE-2018-754840Planlayın
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
KritikCVSS 9,8İstismar yokEPSS %3zsh · zsh27 Şub 2018
- CVE-2018-050240Planlayın
An issue was discovered in zsh before 5.6.
KritikCVSS 9,8İstismar yokEPSS %2zsh · zsh5 Eyl 2018
- CVE-2016-1071440Planlayın
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
KritikCVSS 9,8İstismar yokEPSS %2zsh · zsh27 Şub 2018
- CVE-2021-4544432İzleyin
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argu
YüksekCVSS 7,8İstismar yokEPSS %2zsh · zsh14 Şub 2022
- CVE-2018-754931İzleyin
In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.
YüksekCVSS 7,5İstismar yokEPSS %3zsh · zsh27 Şub 2018
- CVE-2018-108331İzleyin
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality.
YüksekCVSS 7,8İstismar yokEPSS %1zsh · zsh28 Mar 2018
- CVE-2018-110031İzleyin
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function.
YüksekCVSS 7,8İstismar yokEPSS %1zsh · zsh11 Nis 2018
- CVE-2019-2004431İzleyin
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.
YüksekCVSS 7,8İstismar yokEPSS %0zsh · zsh24 Şub 2020
- CVE-2018-107122İzleyin
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function.
OrtaCVSS 5,5İstismar yokEPSS %0zsh · zsh9 Mar 2018
- CVE-2007-620918İzleyin
Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
OrtaCVSS 4,6İstismar yokEPSS %0zsh · zsh3 Ara 2007