Zeros312
CVE-1999-0038 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-09-04 17:24:32.065476+03:00 | ['CWE-120'] | 2024-09-04 17:07:08.502000+03:00 | ffa82fab84ca9789215fef22dbd2ac33ad2f6f5dbe73ef8c713f827bd76a21c5 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.690Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0038', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-09-04T14:24:32.065476Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:ibm:xlock:*:*:*:*:*:*:*:*'], 'vendor': 'ibm', 'product': 'xlock', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-120', 'description': "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-09-04T14:07:08.502Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in xlock program allows local users to execute commands as root.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:29:31.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in xlock program allows local users to execute commands as root.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0038', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0038', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-12T14:37:48.860Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-1657 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | none | yes | partial | 2.0.3 | 2025-01-16 21:06:18.971030+03:00 | ['CWE-916'] | 2025-01-16 21:04:24.473000+03:00 | b7b50240e6fca9df17ab4aeb1f9fedb3016abaa237250356f993df0656ffcd71 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/20215', 'name': 'postgresql-md5-salt-weak-security(20215)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111402558115859&w=2', 'name': '20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111403050902165&w=2', 'name': '20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://archives.postgresql.org/pgsql-admin/2002-08/msg00253.php', 'name': '[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:34:55.633Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1657', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T18:06:18.971030Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-916', 'description': 'CWE-916 Use of Password Hash With Insufficient Computational Effort'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:04:24.473Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-08-21T04:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/20215', 'name': 'postgresql-md5-salt-weak-security(20215)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://marc.info/?l=bugtraq&m=111402558115859&w=2', 'name': '20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=111403050902165&w=2', 'name': '20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://archives.postgresql.org/pgsql-admin/2002-08/msg00253.php', 'name': '[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)', 'tags': ['mailing-list', 'x_refsource_MLIST']}], 'descriptions': [{'lang': 'en', 'value': 'PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/20215', 'name': 'postgresql-md5-salt-weak-security(20215)', 'refsource': 'XF'}, {'url': 'http://marc.info/?l=bugtraq&m=111402558115859&w=2', 'name': '20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=111403050902165&w=2', 'name': '20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'refsource': 'BUGTRAQ'}, {'url': 'http://archives.postgresql.org/pgsql-admin/2002-08/msg00253.php', 'name': '[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)', 'refsource': 'MLIST'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1657', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1657', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:07:04.776Z', 'dateReserved': '2005-04-22T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-04-22T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2001-0667 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | no | partial | 2.0.3 | 2025-01-16 19:14:19.075236+03:00 | ['CWE-88'] | 2025-01-16 19:13:31.088000+03:00 | b38ae22eba25006217d7d26745df2bbec721079fa004d3b3e06eed883202a2a8 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.kb.cert.org/vuls/id/952611', 'name': 'VU#952611', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051', 'name': 'MS01-051', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7260', 'name': 'ie-telnet-command-execution-variant(7260)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.ciac.org/ciac/bulletins/m-024.shtml', 'name': 'M-024', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:30:06.104Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0667', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T16:14:19.075236Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-88', 'description': "CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T16:13:31.088Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-10-10T04:00:00.000Z', 'references': [{'url': 'http://www.kb.cert.org/vuls/id/952611', 'name': 'VU#952611', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051', 'name': 'MS01-051', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7260', 'name': 'ie-telnet-command-execution-variant(7260)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.ciac.org/ciac/bulletins/m-024.shtml', 'name': 'M-024', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC']}], 'descriptions': [{'lang': 'en', 'value': 'Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2002-03-01T15:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.kb.cert.org/vuls/id/952611', 'name': 'VU#952611', 'refsource': 'CERT-VN'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051', 'name': 'MS01-051', 'refsource': 'MS'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7260', 'name': 'ie-telnet-command-execution-variant(7260)', 'refsource': 'XF'}, {'url': 'http://www.ciac.org/ciac/bulletins/m-024.shtml', 'name': 'M-024', 'refsource': 'CIAC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0667', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0667', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T16:14:40.211Z', 'dateReserved': '2001-08-15T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-03-09T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0035 | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N | none | no | partial | 2.0.3 | 2025-10-20 20:43:58.080852+03:00 | ['CWE-364'] | 2025-09-24 21:45:05.945000+03:00 | fd915780738e647a91db45885e1ab2e6b131bd57f295f0a918f73d9fd3ddb8e1 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.758Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0035', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-10-20T17:43:58.080852Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-364', 'description': 'CWE-364 Signal Handler Race Condition'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-09-24T18:45:05.945Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:28:56.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0035', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0035', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-20T17:45:44.427Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-0254 | 3.70 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N | none | no | partial | 2.0.3 | 2025-01-16 20:54:18.251124+03:00 | ['CWE-434'] | 2025-01-16 20:53:56.131000+03:00 | 535bba59d0e8286c0dd947896fd1f0da0c96f6e04cb8e6adf0f5c129b0541ce8 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/12583', 'name': '12583', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=110868948719773&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=full-disclosure&m=110864983905770&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_FULLDISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:05:25.478Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-0254', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:54:18.251124Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-434', 'description': 'CWE-434 Unrestricted Upload of File with Dangerous Type'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:53:56.131Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-02-17T05:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/12583', 'name': '12583', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://marc.info/?l=bugtraq&m=110868948719773&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=full-disclosure&m=110864983905770&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_FULLDISC']}], 'descriptions': [{'lang': 'en', 'value': 'BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/12583', 'name': '12583', 'refsource': 'BID'}, {'url': 'http://marc.info/?l=bugtraq&m=110868948719773&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=full-disclosure&m=110864983905770&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'refsource': 'FULLDISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-0254', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-0254', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:54:22.288Z', 'dateReserved': '2005-02-09T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-02-17T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-0747 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-02-06 00:31:51.729461+03:00 | ['CWE-131'] | 2025-01-16 20:45:17.631000+03:00 | b2a44571032d943be65a3cc2c56679fa0011e44730fdf82e269d02d5e7c0cdfb | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2004_32_apache2.html', 'name': 'SUSE-SA:2004:032', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-463.html', 'name': 'RHSA-2004:463', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17384', 'name': 'apache-env-configuration-bo(17384)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2009/1233', 'name': 'ADV-2009-1233', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://secunia.com/advisories/12540', 'name': '12540', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561', 'name': 'oval:org.mitre.oval:def:11561', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://secunia.com/advisories/34920', 'name': '34920', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.trustix.org/errata/2004/0047/', 'name': '2004-0047', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX', 'x_transferred']}, {'url': 'http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096', 'name': 'MDKSA-2004:096', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml', 'name': 'GLSA-200409-21', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/481998', 'name': 'VU#481998', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1011303', 'name': '1011303', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210422 svn commit: r1074079 [2/3] - in /websites/staging/httpd/trunk/content: ./ apreq/ contribute/ contributors/ dev/ docs-project/ docs/ info/ mod_fcgid/ mod_ftp/ mod_mbox/ mod_smtpd/ modules/ security/ test/ test/flood/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:31:46.612Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0747', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-05T21:31:51.729461Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-131', 'description': 'CWE-131 Incorrect Calculation of Buffer Size'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:45:17.631Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-09-15T00:00:00.000Z', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2004_32_apache2.html', 'name': 'SUSE-SA:2004:032', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-463.html', 'name': 'RHSA-2004:463', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17384', 'name': 'apache-env-configuration-bo(17384)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.vupen.com/english/advisories/2009/1233', 'name': 'ADV-2009-1233', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://secunia.com/advisories/12540', 'name': '12540', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561', 'name': 'oval:org.mitre.oval:def:11561', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://secunia.com/advisories/34920', 'name': '34920', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.trustix.org/errata/2004/0047/', 'name': '2004-0047', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX']}, {'url': 'http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096', 'name': 'MDKSA-2004:096', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml', 'name': 'GLSA-200409-21', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'http://www.kb.cert.org/vuls/id/481998', 'name': 'VU#481998', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://securitytracker.com/id?1011303', 'name': '1011303', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210422 svn commit: r1074079 [2/3] - in /websites/staging/httpd/trunk/content: ./ apreq/ contribute/ contributors/ dev/ docs-project/ docs/ info/ mod_fcgid/ mod_ftp/ mod_mbox/ mod_smtpd/ modules/ security/ test/ test/flood/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2021-06-06T10:08:59.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.novell.com/linux/security/advisories/2004_32_apache2.html', 'name': 'SUSE-SA:2004:032', 'refsource': 'SUSE'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-463.html', 'name': 'RHSA-2004:463', 'refsource': 'REDHAT'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17384', 'name': 'apache-env-configuration-bo(17384)', 'refsource': 'XF'}, {'url': 'http://www.vupen.com/english/advisories/2009/1233', 'name': 'ADV-2009-1233', 'refsource': 'VUPEN'}, {'url': 'http://secunia.com/advisories/12540', 'name': '12540', 'refsource': 'SECUNIA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561', 'name': 'oval:org.mitre.oval:def:11561', 'refsource': 'OVAL'}, {'url': 'http://secunia.com/advisories/34920', 'name': '34920', 'refsource': 'SECUNIA'}, {'url': 'http://www.trustix.org/errata/2004/0047/', 'name': '2004-0047', 'refsource': 'TRUSTIX'}, {'url': 'http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096', 'name': 'MDKSA-2004:096', 'refsource': 'MANDRAKE'}, {'url': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'name': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'refsource': 'MISC'}, {'url': 'http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml', 'name': 'GLSA-200409-21', 'refsource': 'GENTOO'}, {'url': 'http://www.kb.cert.org/vuls/id/481998', 'name': 'VU#481998', 'refsource': 'CERT-VN'}, {'url': 'http://securitytracker.com/id?1011303', 'name': '1011303', 'refsource': 'SECTRACK'}, {'url': 'https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210422 svn commit: r1074079 [2/3] - in /websites/staging/httpd/trunk/content: ./ apreq/ contribute/ contributors/ dev/ docs-project/ docs/ info/ mod_fcgid/ mod_ftp/ mod_mbox/ mod_smtpd/ modules/ security/ test/ test/flood/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0747', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0747', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:47:15.175Z', 'dateReserved': '2004-07-26T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-17T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0012 | 7.00 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L | none | no | partial | 2.0.3 | 2025-04-07 21:20:15.808307+03:00 | ['CWE-290'] | 2025-04-09 20:48:23.039000+03:00 | 8fab048d9db45ceca23c664bea3547e8ac9b2fb027bd0c90a9a3fa8cf072f7f4 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.462Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0012', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-07T18:20:15.808307Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-290', 'description': 'CWE-290 Authentication Bypass by Spoofing'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-09T17:48:23.039Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:24:34.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0012', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0012', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-09T18:30:54.684Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0041 | none | no | partial | 2.0.3 | 2024-09-04 17:09:51.440131+03:00 | 2024-09-17 17:25:12.391000+03:00 | 6b240a78ad9ab7b7b2a82a55b85dedd2d320f76f21651b4f51283fe03aeafb9d | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.067Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0041', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-09-04T14:09:51.440131Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-09-17T14:25:12.391Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in NLS (Natural Language Service).'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:30:20.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in NLS (Natural Language Service).'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0041', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0041', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-17T14:25:15.473Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-1999-0632 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | partial | 2.0.3 | 2026-05-28 20:48:11.820577+03:00 | ['CWE-200'] | 2026-05-28 20:48:04.805000+03:00 | e5c17bac10512543e0778c0b33c1865ff0517c06e3f118c2e27f002ded98a316 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:41:45.686Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0632', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:48:11.820577Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:48:04.805Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The RPC portmapper service is running.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T08:29:40.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'name': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The RPC portmapper service is running.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0632', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0632', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:48:17.662Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-1999-0069 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-08-01 22:51:45.938973+03:00 | ['CWE-119'] | 2024-08-01 22:52:53.361000+03:00 | 47927784c94226c779dd95f8e3f3edc38eb13bd33ceb7ccd63b522e9460fde4c | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/8158', 'name': '8158', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169', 'name': '00169', 'tags': ['vendor-advisory', 'x_refsource_SUN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.100Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0069', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:51:45.938973Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sun:sunos:5.5:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'sunos', 'versions': [{'status': 'affected', 'version': '5.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'sunos', 'versions': [{'status': 'affected', 'version': '5.5.1'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-119', 'description': 'CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:52:53.361Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/8158', 'name': '8158', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169', 'name': '00169', 'tags': ['vendor-advisory', 'x_refsource_SUN']}], 'descriptions': [{'lang': 'en', 'value': 'Solaris ufsrestore buffer overflow.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2004-09-02T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/8158', 'name': '8158', 'refsource': 'OSVDB'}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169', 'name': '00169', 'refsource': 'SUN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Solaris ufsrestore buffer overflow.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0069', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0069', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T19:55:25.041Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-2761 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2026-05-28 21:20:04.495874+03:00 | ['CWE-328'] | 2026-05-28 21:19:58.612000+03:00 | 0a43c238d2c8e0c0168349844018df82434fbcffa267bbf61ebf47af52c6aae6 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/33065', 'name': '33065', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0837.html', 'name': 'RHSA-2010:0837', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.phreedom.org/research/rogue-ca/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/836068', 'name': 'VU#836068', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://securityreason.com/securityalert/4866', 'name': '4866', 'tags': ['third-party-advisory', 'x_refsource_SREASON', 'x_transferred']}, {'url': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html', 'name': '20090115 MD5 Hashes May Allow for Certificate Spoofing', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://secunia.com/advisories/33826', 'name': '33826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/34281', 'name': '34281', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0838.html', 'name': 'RHSA-2010:0838', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-740-1', 'name': 'USN-740-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1024697', 'name': '1024697', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html', 'name': 'FEDORA-2009-1276', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/499685/100/0/threaded', 'name': '20081230 MD5 Considered Harmful Today: Creating a rogue CA certificate', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://secunia.com/advisories/42181', 'name': '42181', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:36:25.448Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2761', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-28T18:20:04.495874Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-328', 'description': 'CWE-328 Use of Weak Hash'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T18:19:58.612Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-08-17T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/33065', 'name': '33065', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0837.html', 'name': 'RHSA-2010:0837', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.phreedom.org/research/rogue-ca/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.kb.cert.org/vuls/id/836068', 'name': 'VU#836068', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://securityreason.com/securityalert/4866', 'name': '4866', 'tags': ['third-party-advisory', 'x_refsource_SREASON']}, {'url': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html', 'name': '20090115 MD5 Hashes May Allow for Certificate Spoofing', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'tags': ['x_refsource_MISC']}, {'url': 'http://secunia.com/advisories/33826', 'name': '33826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/34281', 'name': '34281', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'tags': ['x_refsource_MISC']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0838.html', 'name': 'RHSA-2010:0838', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.ubuntu.com/usn/usn-740-1', 'name': 'USN-740-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://securitytracker.com/id?1024697', 'name': '1024697', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html', 'name': 'FEDORA-2009-1276', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/archive/1/499685/100/0/threaded', 'name': '20081230 MD5 Considered Harmful Today: Creating a rogue CA certificate', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://secunia.com/advisories/42181', 'name': '42181', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/33065', 'name': '33065', 'refsource': 'BID'}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0837.html', 'name': 'RHSA-2010:0837', 'refsource': 'REDHAT'}, {'url': 'http://www.phreedom.org/research/rogue-ca/', 'name': 'http://www.phreedom.org/research/rogue-ca/', 'refsource': 'MISC'}, {'url': 'http://www.kb.cert.org/vuls/id/836068', 'name': 'VU#836068', 'refsource': 'CERT-VN'}, {'url': 'http://securityreason.com/securityalert/4866', 'name': '4866', 'refsource': 'SREASON'}, {'url': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'name': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'refsource': 'MISC'}, {'url': 'http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html', 'name': '20090115 MD5 Hashes May Allow for Certificate Spoofing', 'refsource': 'CISCO'}, {'url': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'name': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'refsource': 'MISC'}, {'url': 'http://secunia.com/advisories/33826', 'name': '33826', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/34281', 'name': '34281', 'refsource': 'SECUNIA'}, {'url': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'name': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'refsource': 'MISC'}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'name': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'refsource': 'CONFIRM'}, {'url': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'name': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'refsource': 'MISC'}, {'url': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'name': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'refsource': 'MISC'}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'name': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'refsource': 'MISC'}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0838.html', 'name': 'RHSA-2010:0838', 'refsource': 'REDHAT'}, {'url': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'name': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'refsource': 'MISC'}, {'url': 'http://www.ubuntu.com/usn/usn-740-1', 'name': 'USN-740-1', 'refsource': 'UBUNTU'}, {'url': 'http://securitytracker.com/id?1024697', 'name': '1024697', 'refsource': 'SECTRACK'}, {'url': 'https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html', 'name': 'FEDORA-2009-1276', 'refsource': 'FEDORA'}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'name': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'refsource': 'CONFIRM'}, {'url': 'http://www.securityfocus.com/archive/1/499685/100/0/threaded', 'name': '20081230 MD5 Considered Harmful Today: Creating a rogue CA certificate', 'refsource': 'BUGTRAQ'}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'name': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'refsource': 'CONFIRM'}, {'url': 'http://secunia.com/advisories/42181', 'name': '42181', 'refsource': 'SECUNIA'}, {'url': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'name': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'refsource': 'MISC'}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2761', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2761', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T18:20:09.605Z', 'dateReserved': '2009-01-05T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2009-01-05T20:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-2004-0458 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2025-01-16 20:35:36.151205+03:00 | ['CWE-476'] | 2025-01-16 20:35:16.531000+03:00 | e59308d0604c56007cad57371c6cd951b23287d697e519dd626aeb39c3711b40 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/10343', 'name': '10343', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16143', 'name': 'mah-jong-null-dos(16143)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.debian.org/security/2004/dsa-503', 'name': 'DSA-503', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:17:14.961Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0458', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:35:36.151205Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-476', 'description': 'CWE-476 NULL Pointer Dereference'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:35:16.531Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-05-13T04:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/10343', 'name': '10343', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16143', 'name': 'mah-jong-null-dos(16143)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.debian.org/security/2004/dsa-503', 'name': 'DSA-503', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}], 'descriptions': [{'lang': 'en', 'value': 'mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/10343', 'name': '10343', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16143', 'name': 'mah-jong-null-dos(16143)', 'refsource': 'XF'}, {'url': 'http://www.debian.org/security/2004/dsa-503', 'name': 'DSA-503', 'refsource': 'DEBIAN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0458', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0458', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:35:50.721Z', 'dateReserved': '2004-05-10T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-08-19T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0052 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2024-08-01 23:17:55.821578+03:00 | ['CWE-476'] | 2024-08-01 23:32:02.473000+03:00 | b37b68456ab57169a17b3c9cfa48d6fb9836857eb6ce252fcf62d9331a2527a3 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1389', 'name': 'freebsd-ip-frag-dos(1389)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.osvdb.org/908', 'name': '908', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.172Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0052', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:17:55.821578Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:bsdi:bsd_os:4.0:*:*:*:*:*:*:*'], 'vendor': 'bsdi', 'product': 'bsd_os', 'versions': [{'status': 'affected', 'version': '4.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:1.1.5.1:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '1.1.5.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0.5:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.5:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.6:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.6'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.7.1:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.7.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.2.2:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.2.2'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.2.8:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.2.8'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:openbsd:openbsd:2.2:*:*:*:*:*:*:*'], 'vendor': 'openbsd', 'product': 'openbsd', 'versions': [{'status': 'affected', 'version': '2.2'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:openbsd:openbsd:2.3:*:*:*:*:*:*:*'], 'vendor': 'openbsd', 'product': 'openbsd', 'versions': [{'status': 'affected', 'version': '2.3'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:openbsd:openbsd:2.4:*:*:*:*:*:*:*'], 'vendor': 'openbsd', 'product': 'openbsd', 'versions': [{'status': 'affected', 'version': '2.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-476', 'description': 'CWE-476 NULL Pointer Dereference'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:32:02.473Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1389', 'name': 'freebsd-ip-frag-dos(1389)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.osvdb.org/908', 'name': '908', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-12-18T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1389', 'name': 'freebsd-ip-frag-dos(1389)', 'refsource': 'XF'}, {'url': 'http://www.osvdb.org/908', 'name': '908', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0052', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0052', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:32:09.970Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2001-0006 | none | no | partial | 2.0.3 | 2024-01-31 18:50:22.565040+03:00 | 2024-12-03 18:42:59.652000+03:00 | 0d37e68025df49b832871d6d2eb211fbc7917bed1b63aac0ba8bfaa1af242452 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=98075221915234&w=2', 'name': '20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003', 'name': 'MS01-003', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6006', 'name': 'winnt-mutex-dos(6006)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:06:54.497Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0006', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-31T15:50:22.565040Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-12-03T15:42:59.652Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-01-24T05:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=98075221915234&w=2', 'name': '20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003', 'name': 'MS01-003', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6006', 'name': 'winnt-mutex-dos(6006)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T15:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=98075221915234&w=2', 'name': '20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below', 'refsource': 'BUGTRAQ'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003', 'name': 'MS01-003', 'refsource': 'MS'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6006', 'name': 'winnt-mutex-dos(6006)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0006', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0006', 'state': 'PUBLISHED', 'dateUpdated': '2024-12-03T15:43:09.651Z', 'dateReserved': '2001-01-04T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-05-07T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-2002-0391 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-02-08 22:26:07.645774+03:00 | ['CWE-190'] | 2025-01-16 20:13:54.722000+03:00 | 66d306658d187d8921c839a07d648e6b8e569b6523715638d105472347c7a680 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.iss.net/security_center/static/9170.php', 'name': 'sunrpc-xdr-array-bo(9170)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A', 'name': '20020801-01-A', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://www.cert.org/advisories/CA-2002-25.html', 'name': 'CA-2002-25', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://online.securityfocus.com/advisories/4402', 'name': 'HPSBTL0208-061', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=103158632831416&w=2', 'name': '20020909 GLSA: glibc', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-146', 'name': 'DSA-146', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-166.html', 'name': 'RHSA-2002:166', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/hp/2002-q3/0077.html', 'name': 'HPSBUX0209-215', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt', 'name': 'CSSA-2002-055.0', 'tags': ['vendor-advisory', 'x_refsource_CALDERA', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-143', 'name': 'DSA-143', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['third-party-advisory', 'x_refsource_ISS', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P', 'name': '20020801-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515', 'name': 'CLA-2002:515', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535', 'name': 'CLA-2002:535', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-212.html', 'name': 'RHSA-2003:212', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057', 'name': 'MS02-057', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-142', 'name': 'DSA-142', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc', 'name': 'NetBSD-SA2002-011', 'tags': ['vendor-advisory', 'x_refsource_NETBSD', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/aix/2002-q4/0002.html', 'name': 'IY34194', 'tags': ['vendor-advisory', 'x_refsource_AIXAPAR', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-167.html', 'name': 'RHSA-2002:167', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html', 'name': '20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102821928418261&w=2', 'name': 'FreeBSD-SA-02:34.rpc', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-173.html', 'name': 'RHSA-2002:173', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/5356', 'name': '5356', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://online.securityfocus.com/archive/1/285740', 'name': '20020802 kerberos rpc xdr_array', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102813809232532&w=2', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102821785316087&w=2', 'name': '20020801 RPC analysis', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/192995', 'name': 'VU#192995', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-172.html', 'name': 'RHSA-2002:172', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728', 'name': 'oval:org.mitre.oval:def:4728', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42', 'name': 'oval:org.mitre.oval:def:42', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.linuxsecurity.com/advisories/other_advisory-2399.html', 'name': 'ESA-20021003-021', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9', 'name': 'oval:org.mitre.oval:def:9', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057', 'name': 'MDKSA-2002:057', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-149', 'name': 'DSA-149', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102831443208382&w=2', 'name': '20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.debian.org/security/2003/dsa-333', 'name': 'DSA-333', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-168.html', 'name': 'RHSA-2003:168', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:49:28.492Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0391', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-08T19:26:07.645774Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-190', 'description': 'CWE-190 Integer Overflow or Wraparound'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:13:54.722Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-07-29T00:00:00.000Z', 'references': [{'url': 'http://www.iss.net/security_center/static/9170.php', 'name': 'sunrpc-xdr-array-bo(9170)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A', 'name': '20020801-01-A', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://www.cert.org/advisories/CA-2002-25.html', 'name': 'CA-2002-25', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://online.securityfocus.com/advisories/4402', 'name': 'HPSBTL0208-061', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://marc.info/?l=bugtraq&m=103158632831416&w=2', 'name': '20020909 GLSA: glibc', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.debian.org/security/2002/dsa-146', 'name': 'DSA-146', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-166.html', 'name': 'RHSA-2002:166', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://archives.neohapsis.com/archives/hp/2002-q3/0077.html', 'name': 'HPSBUX0209-215', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt', 'name': 'CSSA-2002-055.0', 'tags': ['vendor-advisory', 'x_refsource_CALDERA']}, {'url': 'http://www.debian.org/security/2002/dsa-143', 'name': 'DSA-143', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['third-party-advisory', 'x_refsource_ISS']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P', 'name': '20020801-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515', 'name': 'CLA-2002:515', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535', 'name': 'CLA-2002:535', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-212.html', 'name': 'RHSA-2003:212', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057', 'name': 'MS02-057', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.debian.org/security/2002/dsa-142', 'name': 'DSA-142', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc', 'name': 'NetBSD-SA2002-011', 'tags': ['vendor-advisory', 'x_refsource_NETBSD']}, {'url': 'http://archives.neohapsis.com/archives/aix/2002-q4/0002.html', 'name': 'IY34194', 'tags': ['vendor-advisory', 'x_refsource_AIXAPAR']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-167.html', 'name': 'RHSA-2002:167', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html', 'name': '20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=102821928418261&w=2', 'name': 'FreeBSD-SA-02:34.rpc', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-173.html', 'name': 'RHSA-2002:173', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.securityfocus.com/bid/5356', 'name': '5356', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://online.securityfocus.com/archive/1/285740', 'name': '20020802 kerberos rpc xdr_array', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=102813809232532&w=2', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=102821785316087&w=2', 'name': '20020801 RPC analysis', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.kb.cert.org/vuls/id/192995', 'name': 'VU#192995', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-172.html', 'name': 'RHSA-2002:172', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728', 'name': 'oval:org.mitre.oval:def:4728', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42', 'name': 'oval:org.mitre.oval:def:42', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.linuxsecurity.com/advisories/other_advisory-2399.html', 'name': 'ESA-20021003-021', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9', 'name': 'oval:org.mitre.oval:def:9', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057', 'name': 'MDKSA-2002:057', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://www.debian.org/security/2002/dsa-149', 'name': 'DSA-149', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://marc.info/?l=bugtraq&m=102831443208382&w=2', 'name': '20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.debian.org/security/2003/dsa-333', 'name': 'DSA-333', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-168.html', 'name': 'RHSA-2003:168', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}], 'descriptions': [{'lang': 'en', 'value': 'Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2003-03-20T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.iss.net/security_center/static/9170.php', 'name': 'sunrpc-xdr-array-bo(9170)', 'refsource': 'XF'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A', 'name': '20020801-01-A', 'refsource': 'SGI'}, {'url': 'http://www.cert.org/advisories/CA-2002-25.html', 'name': 'CA-2002-25', 'refsource': 'CERT'}, {'url': 'http://online.securityfocus.com/advisories/4402', 'name': 'HPSBTL0208-061', 'refsource': 'HP'}, {'url': 'http://marc.info/?l=bugtraq&m=103158632831416&w=2', 'name': '20020909 GLSA: glibc', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.debian.org/security/2002/dsa-146', 'name': 'DSA-146', 'refsource': 'DEBIAN'}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-166.html', 'name': 'RHSA-2002:166', 'refsource': 'REDHAT'}, {'url': 'http://archives.neohapsis.com/archives/hp/2002-q3/0077.html', 'name': 'HPSBUX0209-215', 'refsource': 'HP'}, {'url': 'ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt', 'name': 'CSSA-2002-055.0', 'refsource': 'CALDERA'}, {'url': 'http://www.debian.org/security/2002/dsa-143', 'name': 'DSA-143', 'refsource': 'DEBIAN'}, {'url': 'http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'refsource': 'ISS'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P', 'name': '20020801-01-P', 'refsource': 'SGI'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515', 'name': 'CLA-2002:515', 'refsource': 'CONECTIVA'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535', 'name': 'CLA-2002:535', 'refsource': 'CONECTIVA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-212.html', 'name': 'RHSA-2003:212', 'refsource': 'REDHAT'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057', 'name': 'MS02-057', 'refsource': 'MS'}, {'url': 'http://www.debian.org/security/2002/dsa-142', 'name': 'DSA-142', 'refsource': 'DEBIAN'}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc', 'name': 'NetBSD-SA2002-011', 'refsource': 'NETBSD'}, {'url': 'http://archives.neohapsis.com/archives/aix/2002-q4/0002.html', 'name': 'IY34194', 'refsource': 'AIXAPAR'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-167.html', 'name': 'RHSA-2002:167', 'refsource': 'REDHAT'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html', 'name': '20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=102821928418261&w=2', 'name': 'FreeBSD-SA-02:34.rpc', 'refsource': 'FREEBSD'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-173.html', 'name': 'RHSA-2002:173', 'refsource': 'REDHAT'}, {'url': 'http://www.securityfocus.com/bid/5356', 'name': '5356', 'refsource': 'BID'}, {'url': 'http://online.securityfocus.com/archive/1/285740', 'name': '20020802 kerberos rpc xdr_array', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=102813809232532&w=2', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=102821785316087&w=2', 'name': '20020801 RPC analysis', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.kb.cert.org/vuls/id/192995', 'name': 'VU#192995', 'refsource': 'CERT-VN'}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-172.html', 'name': 'RHSA-2002:172', 'refsource': 'REDHAT'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728', 'name': 'oval:org.mitre.oval:def:4728', 'refsource': 'OVAL'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42', 'name': 'oval:org.mitre.oval:def:42', 'refsource': 'OVAL'}, {'url': 'http://www.linuxsecurity.com/advisories/other_advisory-2399.html', 'name': 'ESA-20021003-021', 'refsource': 'ENGARDE'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9', 'name': 'oval:org.mitre.oval:def:9', 'refsource': 'OVAL'}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057', 'name': 'MDKSA-2002:057', 'refsource': 'MANDRAKE'}, {'url': 'http://www.debian.org/security/2002/dsa-149', 'name': 'DSA-149', 'refsource': 'DEBIAN'}, {'url': 'http://marc.info/?l=bugtraq&m=102831443208382&w=2', 'name': '20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.debian.org/security/2003/dsa-333', 'name': 'DSA-333', 'refsource': 'DEBIAN'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-168.html', 'name': 'RHSA-2003:168', 'refsource': 'REDHAT'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0391', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0391', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:20:45.514Z', 'dateReserved': '2002-05-28T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2003-04-02T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-0485 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | none | yes | partial | 2.0.3 | 2024-02-05 20:19:31.934437+03:00 | ['CWE-178'] | 2025-01-16 20:05:45.659000+03:00 | 14b9a01b0305c220cbca68e56dead72dfd739e24cf69641bf3162cd9983a0e37 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=vuln-dev&m=101681724810317&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_VULN-DEV', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=101684260510079&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:49:28.482Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0485', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-05T17:19:31.934437Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-178', 'description': 'CWE-178 Improper Handling of Case Sensitivity'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:05:45.659Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-03-22T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=vuln-dev&m=101681724810317&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_VULN-DEV']}, {'url': 'http://marc.info/?l=bugtraq&m=101684260510079&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T13:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=vuln-dev&m=101681724810317&w=2', 'name': '20020322 One more way to bypass NAV', 'refsource': 'VULN-DEV'}, {'url': 'http://marc.info/?l=bugtraq&m=101684260510079&w=2', 'name': '20020322 One more way to bypass NAV', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0485', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0485', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:07:29.547Z', 'dateReserved': '2002-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-06-11T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0011 | 5.40 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L | none | no | partial | 2.0.3 | 2025-04-07 21:22:05.623556+03:00 | ['CWE-1067'] | 2025-04-07 21:56:08.140000+03:00 | b52d33ed400f05cc5ae219e38504225b3e2e9e97b67a980529d018eb391c0006 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX', 'name': '19980603-01-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083', 'name': 'HPSBUX9808-083', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180', 'name': '00180', 'tags': ['vendor-advisory', 'x_refsource_SUN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.479Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0011', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-07T18:22:05.623556Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-1067', 'description': 'CWE-1067 Excessive Execution of Sequential Searches of Data Resource'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T18:56:08.140Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX', 'name': '19980603-01-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083', 'name': 'HPSBUX9808-083', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180', 'name': '00180', 'tags': ['vendor-advisory', 'x_refsource_SUN']}], 'descriptions': [{'lang': 'en', 'value': 'Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2009-03-02T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX', 'name': '19980603-01-PX', 'refsource': 'SGI'}, {'url': 'http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083', 'name': 'HPSBUX9808-083', 'refsource': 'HP'}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180', 'name': '00180', 'refsource': 'SUN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0011', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0011', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-09T18:29:26.012Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-2339 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-03-21 19:25:19.376306+03:00 | 2025-01-16 22:37:51.415000+03:00 | a9447edbd90cb0b532cfaaeecc51cdf117276f1b18d4fd53e5677a0293d35af9 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securitytracker.com/id?1009128', 'name': '1009128', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/354392', 'name': '20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15263', 'name': 'win-kernel-gain-privileges(15263)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:22:13.688Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2339', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-03-21T16:25:19.376306Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:37:51.415Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-02-18T05:00:00.000Z', 'references': [{'url': 'http://www.securitytracker.com/id?1009128', 'name': '1009128', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/354392', 'name': '20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15263', 'name': 'win-kernel-gain-privileges(15263)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securitytracker.com/id?1009128', 'name': '1009128', 'refsource': 'SECTRACK'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/354392', 'name': '20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'refsource': 'BUGTRAQ'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'refsource': 'BUGTRAQ'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15263', 'name': 'win-kernel-gain-privileges(15263)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2339', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2339', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:40:39.858Z', 'dateReserved': '2005-08-16T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-08-16T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2001-1546 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2025-01-16 22:32:50.230975+03:00 | ['CWE-326'] | 2025-01-16 22:32:39.530000+03:00 | af26f55d6ff9cf675c76b78c0c12eb71961cc070742e4c71aee353a01b69a62c | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.iss.net/security_center/static/7682.php', 'name': 'pathways-homecare-weak-encryption(7682)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/3653', 'name': '3653', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/244367', 'name': '20011207 Weak Encryption Vulnerability in Pathways Homecare', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:58:11.457Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-1546', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:32:50.230975Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-326', 'description': 'CWE-326 Inadequate Encryption Strength'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:32:39.530Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.iss.net/security_center/static/7682.php', 'name': 'pathways-homecare-weak-encryption(7682)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/bid/3653', 'name': '3653', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.securityfocus.com/archive/1/244367', 'name': '20011207 Weak Encryption Vulnerability in Pathways Homecare', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-14T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.iss.net/security_center/static/7682.php', 'name': 'pathways-homecare-weak-encryption(7682)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/bid/3653', 'name': '3653', 'refsource': 'BID'}, {'url': 'http://www.securityfocus.com/archive/1/244367', 'name': '20011207 Weak Encryption Vulnerability in Pathways Homecare', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-1546', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-1546', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:33:06.252Z', 'dateReserved': '2005-07-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-1816 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-02-16 19:45:29.048974+03:00 | ['CWE-193'] | 2025-01-16 22:26:18.368000+03:00 | aa5b2d5375a5a8f49d7210672dc4d0ef3db1b83cbecbc3e3e187651a5d2e5289 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/5956', 'name': '5956', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/7293', 'name': '7293', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-10/0187.html', 'name': '20021012 Pyramid Research Project - atphttpd security advisorie', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/10362.php', 'name': 'atphttpd-sockgets-bo(10362)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:43:32.518Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1816', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-16T16:45:29.048974Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-193', 'description': 'CWE-193 Off-by-one Error'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:26:18.368Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-10-12T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/5956', 'name': '5956', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/7293', 'name': '7293', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-10/0187.html', 'name': '20021012 Pyramid Research Project - atphttpd security advisorie', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.iss.net/security_center/static/10362.php', 'name': 'atphttpd-sockgets-bo(10362)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-06T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/5956', 'name': '5956', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/7293', 'name': '7293', 'refsource': 'SECUNIA'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-10/0187.html', 'name': '20021012 Pyramid Research Project - atphttpd security advisorie', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.iss.net/security_center/static/10362.php', 'name': 'atphttpd-sockgets-bo(10362)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1816', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1816', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:26:26.128Z', 'dateReserved': '2005-06-29T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-28T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-1588 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-08-01 21:55:51.139162+03:00 | ['CWE-119'] | 2024-08-01 22:00:04.677000+03:00 | 208c8f510808244c1aa598e887c3df6e471365accd6d0931632a7cbabc652426 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/2319', 'name': '2319', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T17:18:07.629Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-1588', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T18:55:51.139162Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sun:solaris:2.4:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '2.4'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:solaris:2.5:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '2.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:solaris:2.5.1:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '2.5.1'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-119', 'description': 'CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:00:04.677Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/2319', 'name': '2319', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'tags': ['x_refsource_MISC']}, {'url': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-04-21T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'name': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/2319', 'name': '2319', 'refsource': 'BID'}, {'url': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'name': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'refsource': 'MISC'}, {'url': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'name': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-1588', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-1588', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T18:19:09.412Z', 'dateReserved': '2006-04-21T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-04-21T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2001-1533 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | none | yes | partial | 2.0.3 | 2024-03-21 18:57:24.602314+03:00 | 2025-01-16 22:29:07.567000+03:00 | 73098b1e449bd9894c25d57e4499a798aa15983566f2c50ce4bc8c3a5be252c9 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/3501', 'name': '3501', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/7446.php', 'name': 'isa-udp-flood-dos(7446)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html', 'name': '20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html', 'name': '20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:58:11.600Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-1533', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-03-21T15:57:24.602314Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:29:07.567Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/bid/3501', 'name': '3501', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.iss.net/security_center/static/7446.php', 'name': 'isa-udp-flood-dos(7446)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html', 'name': '20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html', 'name': '20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-14T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/3501', 'name': '3501', 'refsource': 'BID'}, {'url': 'http://www.iss.net/security_center/static/7446.php', 'name': 'isa-udp-flood-dos(7446)', 'refsource': 'XF'}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html', 'name': '20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'refsource': 'BUGTRAQ'}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html', 'name': '20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-1533', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-1533', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:29:17.831Z', 'dateReserved': '2005-07-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-1999-0524 | 4.00 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | none | no | partial | 2.0.3 | 2026-05-28 20:44:13.487206+03:00 | ['CWE-200'] | 2026-05-28 20:44:09.438000+03:00 | 091571bc39272694d99c271ae6b2eb4ad1e7546ee1b399afcb768619c3e4d99c | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/322', 'name': 'icmp-timestamp(322)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://descriptions.securescout.com/tc/11010', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/306', 'name': 'icmp-netmask(306)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://descriptions.securescout.com/tc/11011', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/95', 'name': '95', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://support.f5.com/csp/article/K15277'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2025-03-17T15:03:25.141Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0524', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:44:13.487206Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:44:09.438Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/322', 'name': 'icmp-timestamp(322)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://descriptions.securescout.com/tc/11010', 'tags': ['x_refsource_MISC']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/306', 'name': 'icmp-netmask(306)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://descriptions.securescout.com/tc/11011', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/95', 'name': '95', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'tags': ['x_refsource_MISC']}, {'url': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/322', 'name': 'icmp-timestamp(322)', 'refsource': 'XF'}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'name': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'refsource': 'CONFIRM'}, {'url': 'http://descriptions.securescout.com/tc/11010', 'name': 'http://descriptions.securescout.com/tc/11010', 'refsource': 'MISC'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/306', 'name': 'icmp-netmask(306)', 'refsource': 'XF'}, {'url': 'http://descriptions.securescout.com/tc/11011', 'name': 'http://descriptions.securescout.com/tc/11011', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/95', 'name': '95', 'refsource': 'OSVDB'}, {'url': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'name': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'refsource': 'MISC'}, {'url': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'name': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0524', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0524', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:44:18.231Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-1999-0511 | 9.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H | none | yes | total | 2.0.3 | 2026-05-28 20:30:53.896976+03:00 | ['CWE-200'] | 2026-05-28 20:30:47.851000+03:00 | 653fcb3dcc7aec276c036f452a2e7a4aa63be418c25126efd90c5b9c5d1815a7 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:41:45.609Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0511', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:30:53.896976Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:30:47.851Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'IP forwarding is enabled on a machine which is not a router or firewall.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T08:26:28.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'name': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IP forwarding is enabled on a machine which is not a router or firewall.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0511', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0511', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:30:57.864Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-1999-0006 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-08-01 21:51:01.909711+03:00 | ['CWE-125'] | 2024-08-01 21:53:30.423000+03:00 | e2ab2c2809b0aecf3e0980ade206478b8e284f785dcf91938f8c554590a29c80 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I', 'name': '19980801-01-I', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/133', 'name': '133', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.465Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0006', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T18:51:01.909711Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:qualcomm:qpopper:2.4:*:*:*:*:*:*:*'], 'vendor': 'qualcomm', 'product': 'qpopper', 'versions': [{'status': 'affected', 'version': '2.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T18:53:30.423Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I', 'name': '19980801-01-I', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://www.securityfocus.com/bid/133', 'name': '133', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': "Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I', 'name': '19980801-01-I', 'refsource': 'SGI'}, {'url': 'http://www.securityfocus.com/bid/133', 'name': '133', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0006', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0006', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:08:55.394Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-1975 | 5.50 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | none | no | partial | 2.0.3 | 2024-02-14 21:32:35.113838+03:00 | ['CWE-326'] | 2025-01-16 22:27:02.927000+03:00 | 8e45c83faa8a7c970158d4f4a0049c6c25f8b807c9c0bfea9b36d9c4761310c9 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://online.securityfocus.com/archive/1/281437', 'name': '20020710 Multiple Security Vulnerabilities in Sharp Zaurus', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/5201', 'name': '5201', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/9535.php', 'name': 'zaurus-passcode-weak-encryption(9535)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:43:33.674Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1975', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-14T18:32:35.113838Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-326', 'description': 'CWE-326 Inadequate Encryption Strength'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:27:02.927Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://online.securityfocus.com/archive/1/281437', 'name': '20020710 Multiple Security Vulnerabilities in Sharp Zaurus', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/5201', 'name': '5201', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.iss.net/security_center/static/9535.php', 'name': 'zaurus-passcode-weak-encryption(9535)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-06-28T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://online.securityfocus.com/archive/1/281437', 'name': '20020710 Multiple Security Vulnerabilities in Sharp Zaurus', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/5201', 'name': '5201', 'refsource': 'BID'}, {'url': 'http://www.iss.net/security_center/static/9535.php', 'name': 'zaurus-passcode-weak-encryption(9535)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1975', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1975', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:27:36.964Z', 'dateReserved': '2005-06-28T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-28T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0022 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-08-01 22:04:07.612814+03:00 | ['CWE-125'] | 2024-08-01 22:13:12.881000+03:00 | 663b230474c1db0d1ad38afabaa0063a97725bd123aa4a4db9b248374efc584f | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179', 'name': '00179', 'tags': ['vendor-advisory', 'x_refsource_SUN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.096Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0022', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:04:07.612814Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:*:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.0'}, {'status': 'affected', 'version': '5.0.1'}, {'status': 'affected', 'version': '5.1'}, {'status': 'affected', 'version': '5.1.1'}, {'status': 'affected', 'version': '5.2'}, {'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '6.0'}, {'status': 'affected', 'version': '6.0.1'}, {'status': 'affected', 'version': '6.1'}, {'status': 'affected', 'version': '6.2'}, {'status': 'affected', 'version': '6.3'}, {'status': 'affected', 'version': '6.4'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sgi:irix:5.3:*:xfs:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.3'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sgi:irix:6.0.1:*:xfs:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '6.0.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:bsdi:bsd_os:1.1:*:*:*:*:*:*:*'], 'vendor': 'bsdi', 'product': 'bsd_os', 'versions': [{'status': 'affected', 'version': '1.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0.5:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:hp:hp-ux:10.00:*:*:*:*:*:*:*'], 'vendor': 'hp', 'product': 'hp-ux', 'versions': [{'status': 'affected', 'version': '10.00'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:ibm:aix:3.1:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:3.2:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:3.2.4:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:3.2.5:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.2:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.3:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.4:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.5:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.2:*:*:*:*:*:*:*'], 'vendor': 'ibm', 'product': 'aix', 'versions': [{'status': 'affected', 'version': '3.1'}, {'status': 'affected', 'version': '3.2'}, {'status': 'affected', 'version': '3.2.4'}, {'status': 'affected', 'version': '3.2.5'}, {'status': 'affected', 'version': '4.1'}, {'status': 'affected', 'version': '4.1.1'}, {'status': 'affected', 'version': '4.1.2'}, {'status': 'affected', 'version': '4.1.3'}, {'status': 'affected', 'version': '4.1.4'}, {'status': 'affected', 'version': '4.1.5'}, {'status': 'affected', 'version': '4.2'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:solaris:4.1.3:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '4.1.3'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:sunos:4.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:4.1.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:4.1.3u1:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.4:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'sunos', 'versions': [{'status': 'affected', 'version': '4.1.1'}, {'status': 'affected', 'version': '4.1.2'}, {'status': 'affected', 'version': '4.1.3u1'}, {'status': 'affected', 'version': '5.0'}, {'status': 'affected', 'version': '5.1'}, {'status': 'affected', 'version': '5.2'}, {'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '5.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:13:12.881Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179', 'name': '00179', 'tags': ['vendor-advisory', 'x_refsource_SUN']}], 'descriptions': [{'lang': 'en', 'value': 'Local user gains root privileges via buffer overflow in rdist, via expstr() function.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179', 'name': '00179', 'refsource': 'SUN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Local user gains root privileges via buffer overflow in rdist, via expstr() function.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0022', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0022', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:08:24.263Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0084 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-08-01 23:30:39.205373+03:00 | ['CWE-269'] | 2024-08-01 23:34:01.143000+03:00 | 59132a2893d56257022f79ac89b54c40159c19a7f81a692a579dddcd63cf8ee8 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/78', 'name': 'nfs-mknod(78)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.559Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0084', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:30:39.205373Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:sun:nfs:*:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'nfs', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '4.1.3', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-269', 'description': 'CWE-269 Improper Privilege Management'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:34:01.143Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/78', 'name': 'nfs-mknod(78)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/78', 'name': 'nfs-mknod(78)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0084', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0084', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:39:56.806Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-2320 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | none | yes | partial | 2.0.3 | 2026-05-28 20:54:59.137685+03:00 | ['CWE-200'] | 2026-05-28 20:54:53.051000+03:00 | eedb2ee740e4475f622cc5b51186cd74c15253732a89a3c3ff2be562879a220a | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/14959', 'name': 'weblogic-trace-xss(14959)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/867593', 'name': 'VU#867593', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://dev2dev.bea.com/pub/advisory/68', 'name': 'BEA04-48.01', 'tags': ['vendor-advisory', 'x_refsource_BEA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/9506', 'name': '9506', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/10726', 'name': '10726', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securitytracker.com/alerts/2004/Jan/1008866.html', 'name': '1008866', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.osvdb.org/3726', 'name': '3726', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:22:13.662Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2320', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:54:59.137685Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:54:53.051Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-01-27T00:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/14959', 'name': 'weblogic-trace-xss(14959)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.kb.cert.org/vuls/id/867593', 'name': 'VU#867593', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://dev2dev.bea.com/pub/advisory/68', 'name': 'BEA04-48.01', 'tags': ['vendor-advisory', 'x_refsource_BEA']}, {'url': 'http://www.securityfocus.com/bid/9506', 'name': '9506', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/10726', 'name': '10726', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securitytracker.com/alerts/2004/Jan/1008866.html', 'name': '1008866', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.osvdb.org/3726', 'name': '3726', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/14959', 'name': 'weblogic-trace-xss(14959)', 'refsource': 'XF'}, {'url': 'http://www.kb.cert.org/vuls/id/867593', 'name': 'VU#867593', 'refsource': 'CERT-VN'}, {'url': 'http://dev2dev.bea.com/pub/advisory/68', 'name': 'BEA04-48.01', 'refsource': 'BEA'}, {'url': 'http://www.securityfocus.com/bid/9506', 'name': '9506', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/10726', 'name': '10726', 'refsource': 'SECUNIA'}, {'url': 'http://www.securitytracker.com/alerts/2004/Jan/1008866.html', 'name': '1008866', 'refsource': 'SECTRACK'}, {'url': 'http://www.osvdb.org/3726', 'name': '3726', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2320', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2320', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:55:12.478Z', 'dateReserved': '2005-08-16T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-08-16T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-1999-1568 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2025-01-16 20:39:39.255679+03:00 | ['CWE-193'] | 2025-01-16 20:40:02.933000+03:00 | fe5bfb67d4e83ad0e8ffbde8c56d2348137c9c7c54eeb6237d8a1a1024f10de6 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/12699', 'name': '19990223 Comments on NcFTPd "theoretical root compromise"', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1833', 'name': 'ncftpd-port-bo(1833)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=91981352617720&w=2', 'name': '19990223 NcFTPd remote buffer overflow', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T17:18:07.549Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-1568', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:39:39.255679Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-193', 'description': 'CWE-193 Off-by-one Error'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:40:02.933Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '1999-02-23T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/12699', 'name': '19990223 Comments on NcFTPd "theoretical root compromise"', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1833', 'name': 'ncftpd-port-bo(1833)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://marc.info/?l=bugtraq&m=91981352617720&w=2', 'name': '19990223 NcFTPd remote buffer overflow', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2003-03-21T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/12699', 'name': '19990223 Comments on NcFTPd "theoretical root compromise"', 'refsource': 'BUGTRAQ'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1833', 'name': 'ncftpd-port-bo(1833)', 'refsource': 'XF'}, {'url': 'http://marc.info/?l=bugtraq&m=91981352617720&w=2', 'name': '19990223 NcFTPd remote buffer overflow', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-1568', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-1568', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:40:42.694Z', 'dateReserved': '2001-08-31T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-01T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0036 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-08-01 22:38:13.056705+03:00 | ['CWE-434'] | 2024-08-01 22:44:45.984000+03:00 | c3d04f2ab9106efbe19d9a5185a968e46eea2a1b308a014397fc9b8c5a1c8f13 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/990', 'name': '990', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.ciac.org/ciac/bulletins/h-106.shtml', 'name': 'H-106', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX', 'name': '19970508-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/557', 'name': 'sgi-lockout(557)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.712Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0036', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:38:13.056705Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:5.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:xfs:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.4:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.0'}, {'status': 'affected', 'version': '5.0.1'}, {'status': 'affected', 'version': '5.1'}, {'status': 'affected', 'version': '5.1.1'}, {'status': 'affected', 'version': '5.2'}, {'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '6.0'}, {'status': 'affected', 'version': '6.0.1'}, {'status': 'affected', 'version': '6.1'}, {'status': 'affected', 'version': '6.2'}, {'status': 'affected', 'version': '6.3'}, {'status': 'affected', 'version': '6.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-434', 'description': 'CWE-434 Unrestricted Upload of File with Dangerous Type'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:44:45.984Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/990', 'name': '990', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.ciac.org/ciac/bulletins/h-106.shtml', 'name': 'H-106', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX', 'name': '19970508-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/557', 'name': 'sgi-lockout(557)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/990', 'name': '990', 'refsource': 'OSVDB'}, {'url': 'http://www.ciac.org/ciac/bulletins/h-106.shtml', 'name': 'H-106', 'refsource': 'CIAC'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX', 'name': '19970508-02-PX', 'refsource': 'SGI'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/557', 'name': 'sgi-lockout(557)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0036', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0036', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:07:28.583Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-0369 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | none | yes | partial | 2.0.3 | 2024-02-09 22:37:41.057871+03:00 | ['CWE-129'] | 2025-01-16 20:49:02.640000+03:00 | fbb81ca75a59cd1b2276932e5bdd8a8cbd2728aa99c6024723844ce84af601af | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=110811699206052&w=2', 'name': '20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:13:53.455Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-0369', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-09T19:37:41.057871Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-129', 'description': 'CWE-129 Improper Validation of Array Index'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:49:02.640Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-02-10T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=110811699206052&w=2', 'name': '20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T13:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=110811699206052&w=2', 'name': '20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-0369', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-0369', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:49:34.444Z', 'dateReserved': '2005-02-11T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-02-11T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-1464 | 5.90 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H | active | no | partial | 2.0.3 | 2025-02-07 17:29:07.632839+03:00 | ['CWE-400'] | 2025-02-07 17:28:43.653000+03:00 | 9914dc0dd395e54c17e173072ab2a2b221153098c490c1b1f3ab2009d4f1e32a | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17131', 'name': 'cisco-ios-telnet-dos(17131)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1011079', 'name': '1011079', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/384230', 'name': 'VU#384230', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://secunia.com/advisories/12395/', 'name': '12395', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml', 'name': '20040827 Cisco Telnet Denial of Service Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/11060', 'name': '11060', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:53:23.947Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-1464', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:29:07.632839Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2023-05-19', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-1464'}}}], 'timeline': [{'lang': 'en', 'time': '2023-05-19T00:00:00.000Z', 'value': 'CVE-2004-1464 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-1464', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:28:43.653Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-08-27T00:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17131', 'name': 'cisco-ios-telnet-dos(17131)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://securitytracker.com/id?1011079', 'name': '1011079', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.kb.cert.org/vuls/id/384230', 'name': 'VU#384230', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://secunia.com/advisories/12395/', 'name': '12395', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml', 'name': '20040827 Cisco Telnet Denial of Service Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://www.securityfocus.com/bid/11060', 'name': '11060', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17131', 'name': 'cisco-ios-telnet-dos(17131)', 'refsource': 'XF'}, {'url': 'http://securitytracker.com/id?1011079', 'name': '1011079', 'refsource': 'SECTRACK'}, {'url': 'http://www.kb.cert.org/vuls/id/384230', 'name': 'VU#384230', 'refsource': 'CERT-VN'}, {'url': 'http://secunia.com/advisories/12395/', 'name': '12395', 'refsource': 'SECUNIA'}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml', 'name': '20040827 Cisco Telnet Denial of Service Vulnerability', 'refsource': 'CISCO'}, {'url': 'http://www.securityfocus.com/bid/11060', 'name': '11060', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-1464', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-1464', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.162Z', 'dateReserved': '2005-02-13T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-02-13T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2003-20001 | 5.60 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L | none | no | partial | 2.0.3 | 2025-04-04 23:20:21.648275+03:00 | ['CWE-200'] | 2025-04-04 23:22:04.492000+03:00 | d142801479bb35c5484b8a8a6c9152ac547f377dea3a13e8f3035bd84804536d | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.6, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2003-20001', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-04T20:20:21.648275Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-04T20:22:04.492Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://packetstorm.news/files/id/31445'}, {'url': 'http://olografix.org/acme/mitel.txt'}, {'url': 'https://rb.gy/1smt22'}, {'url': 'https://www.exploit-db.com/exploits/49176'}], 'descriptions': [{'lang': 'en', 'value': 'An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2025-04-01T21:01:21.094Z'}}}, 'cveMetadata': {'cveId': 'CVE-2003-20001', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-04T20:22:13.607Z', 'dateReserved': '2025-03-28T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2025-04-01T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-1796 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-02-09 20:57:39.682936+03:00 | ['CWE-347'] | 2025-01-16 22:23:32.490000+03:00 | 57f0e0f7b730a2b9e2d7062b85fc785662562b227264ef8e9fdea67c3852bb34 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/5334', 'name': '5334', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://online.securityfocus.com/advisories/4317', 'name': 'HPSBUX0207-203', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/9695.php', 'name': 'hp-chaivm-add-services(9695)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/284648', 'name': '20020227 Phenoelit Advisory #0815 +--', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:34:56.348Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1796', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-09T17:57:39.682936Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-347', 'description': 'CWE-347 Improper Verification of Cryptographic Signature'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:23:32.490Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/5334', 'name': '5334', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://online.securityfocus.com/advisories/4317', 'name': 'HPSBUX0207-203', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.iss.net/security_center/static/9695.php', 'name': 'hp-chaivm-add-services(9695)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/archive/1/284648', 'name': '20020227 Phenoelit Advisory #0815 +--', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-06-28T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'name': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/5334', 'name': '5334', 'refsource': 'BID'}, {'url': 'http://online.securityfocus.com/advisories/4317', 'name': 'HPSBUX0207-203', 'refsource': 'HP'}, {'url': 'http://www.iss.net/security_center/static/9695.php', 'name': 'hp-chaivm-add-services(9695)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/archive/1/284648', 'name': '20020227 Phenoelit Advisory #0815 +--', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1796', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1796', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:24:39.019Z', 'dateReserved': '2005-06-28T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-28T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0517 | 5.90 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | no | partial | 2.0.3 | 2026-05-28 20:34:44.093859+03:00 | ['CWE-200'] | 2026-05-28 20:34:40.117000+03:00 | 134669fa31e4dd0ceff0cf77679ffdc7b5bc708e21b791a4cb783f577f7f2c2e | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-244'}, {'url': 'https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-244/'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2025-03-17T15:03:23.650Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0517', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:34:44.093859Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:34:40.117Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An SNMP community name is the default (e.g. public), null, or missing.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T07:45:39.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An SNMP community name is the default (e.g. public), null, or missing.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0517', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0517', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:34:53.144Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-2005-10004 | poc | no | total | 2.0.3 | 2025-09-02 23:43:58.409178+03:00 | 2025-09-02 23:44:05.677000+03:00 | e8e0887ee0f0aa047094c6f854b27a65c81b1b94b063300bedb968c66cca8f52 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-10004', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'poc'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-09-02T20:43:58.409178Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-09-02T20:44:05.677Z'}}], 'cna': {'title': 'Cacti graph_view.php RCE via graph_start Parameter Injection', 'source': {'discovery': 'UNKNOWN'}, 'credits': [{'lang': 'en', 'type': 'finder', 'value': 'David Maciejak'}], 'impacts': [{'capecId': 'CAPEC-88', 'descriptions': [{'lang': 'en', 'value': 'CAPEC-88 OS Command Injection'}]}], 'metrics': [{'format': 'CVSS', 'cvssV4_0': {'Safety': 'NOT_DEFINED', 'version': '4.0', 'Recovery': 'NOT_DEFINED', 'baseScore': 8.7, 'Automatable': 'NOT_DEFINED', 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'valueDensity': 'NOT_DEFINED', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'providerUrgency': 'NOT_DEFINED', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH', 'vulnerabilityResponseEffort': 'NOT_DEFINED'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'Raxnet/Ian Berry', 'modules': ['graph_view.php (web interface script responsible for rendering graphs)'], 'product': 'Cacti', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '0.8.6-d', 'versionType': 'semver'}], 'defaultStatus': 'unaffected'}], 'datePublic': '2005-01-15T00:00:00.000Z', 'references': [{'url': 'https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/cacti_graphimage_exec.rb', 'tags': ['exploit']}, {'url': 'https://www.exploit-db.com/exploits/9911', 'tags': ['exploit']}, {'url': 'https://www.exploit-db.com/exploits/16881', 'tags': ['exploit']}, {'url': 'https://www.cacti.net/info/downloads', 'tags': ['product']}, {'url': 'https://web.archive.org/web/20050305034552/http://www.cacti.net/cactid_download.php', 'tags': ['product', 'patch']}, {'url': 'https://www.vulncheck.com/advisories/cacti-graph-view-rce', 'tags': ['third-party-advisory']}], 'x_generator': {'engine': 'Vulnogram 0.2.0'}, 'descriptions': [{'lang': 'en', 'value': 'Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.', 'supportingMedia': [{'type': 'text/html', 'value': 'Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.', 'base64': False}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], 'providerMetadata': {'orgId': '83251b91-4cc7-4094-a5c7-464a1b83ea10', 'shortName': 'VulnCheck', 'dateUpdated': '2026-05-15T11:13:09.188Z'}}}, 'cveMetadata': {'cveId': 'CVE-2005-10004', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-15T11:13:09.188Z', 'dateReserved': '2025-08-28T18:08:00.944Z', 'assignerOrgId': '83251b91-4cc7-4094-a5c7-464a1b83ea10', 'datePublished': '2025-08-30T13:45:16.222Z', 'assignerShortName': 'VulnCheck'}, 'dataVersion': '5.2'} | ||||
CVE-2004-2257 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | none | yes | partial | 2.0.3 | 2024-01-30 19:36:54.394607+03:00 | ['CWE-425'] | 2025-01-16 22:34:51.596000+03:00 | b911d89d6a8625450d5c6c554403eec1374101bf2ab6da24d96ce91bfc07cc3b | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/8240', 'name': '8240', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1010795', 'name': '1010795', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://secunia.com/advisories/12085', 'name': '12085', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16814', 'name': 'phpmyfaq-authentication-bypass(16814)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/10813', 'name': '10813', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:22:13.486Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2257', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-30T16:36:54.394607Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-425', 'description': "CWE-425 Direct Request ('Forced Browsing')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:34:51.596Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-07-27T00:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/8240', 'name': '8240', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://securitytracker.com/id?1010795', 'name': '1010795', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://secunia.com/advisories/12085', 'name': '12085', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16814', 'name': 'phpmyfaq-authentication-bypass(16814)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/bid/10813', 'name': '10813', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/8240', 'name': '8240', 'refsource': 'OSVDB'}, {'url': 'http://securitytracker.com/id?1010795', 'name': '1010795', 'refsource': 'SECTRACK'}, {'url': 'http://secunia.com/advisories/12085', 'name': '12085', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16814', 'name': 'phpmyfaq-authentication-bypass(16814)', 'refsource': 'XF'}, {'url': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'name': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'refsource': 'CONFIRM'}, {'url': 'http://www.securityfocus.com/bid/10813', 'name': '10813', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2257', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2257', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:34:58.763Z', 'dateReserved': '2005-07-17T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-17T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-0051 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2025-01-16 20:12:27.298249+03:00 | ['CWE-667'] | 2025-01-16 20:11:29.033000+03:00 | 546ccdf134ac71bd0ff8869894de8c0c9a578aa384a8858ba63acbafed85962e | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://online.securityfocus.com/archive/1/244329', 'name': '20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A38', 'name': 'oval:org.mitre.oval:def:38', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-016', 'name': 'MS02-016', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/4438', 'name': '4438', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:35:17.461Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0051', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:12:27.298249Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-667', 'description': 'CWE-667 Improper Locking'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:11:29.033Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-04-04T00:00:00.000Z', 'references': [{'url': 'http://online.securityfocus.com/archive/1/244329', 'name': '20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A38', 'name': 'oval:org.mitre.oval:def:38', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-016', 'name': 'MS02-016', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.securityfocus.com/bid/4438', 'name': '4438', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2002-06-16T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://online.securityfocus.com/archive/1/244329', 'name': '20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain)', 'refsource': 'BUGTRAQ'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A38', 'name': 'oval:org.mitre.oval:def:38', 'refsource': 'OVAL'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-016', 'name': 'MS02-016', 'refsource': 'MS'}, {'url': 'http://www.securityfocus.com/bid/4438', 'name': '4438', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0051', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0051', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:12:31.750Z', 'dateReserved': '2002-02-02T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-06-25T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-20002 | none | no | partial | 2.0.3 | 2025-01-07 00:08:18.044511+03:00 | 2025-01-07 00:08:24.787000+03:00 | 03c08c9743350f89247ef89db0893735ec1cbea6486bccb07b81af191066d9d1 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-20002', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-06T21:08:18.044511Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-06T21:08:24.787Z'}}], 'cna': {'metrics': [{'cvssV3_1': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}}], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://metacpan.org/release/MNAGUIB/EasyTCP-0.26/changes'}, {'url': 'https://github.com/briandfoy/cpan-security-advisory/issues/184'}, {'url': 'https://metacpan.org/release/MNAGUIB/EasyTCP-0.15/view/EasyTCP.pm'}], 'x_generator': {'engine': 'enrichogram 0.0.1'}, 'descriptions': [{'lang': 'en', 'value': "The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-338', 'description': 'CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2025-01-02T05:00:27.855Z'}}}, 'cveMetadata': {'cveId': 'CVE-2002-20002', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-06T21:08:29.156Z', 'dateReserved': '2025-01-02T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2025-01-02T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-1999-0059 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | partial | 2.0.3 | 2024-08-01 23:34:06.831485+03:00 | ['CWE-200'] | 2024-08-01 23:35:42.893000+03:00 | bdcde216710505074c597969643b5a56ec17fde51bbe0355cde190340fc2e259 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/164', 'name': '164', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/353', 'name': '353', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/325', 'name': 'irix-fam(325)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.256Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0059', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:34:06.831485Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.3:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '6.1'}, {'status': 'affected', 'version': '6.2'}, {'status': 'affected', 'version': '6.3'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:35:42.893Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/164', 'name': '164', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/353', 'name': '353', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/325', 'name': 'irix-fam(325)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'IRIX fam service allows an attacker to obtain a list of all files on the server.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/164', 'name': '164', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/353', 'name': '353', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/325', 'name': 'irix-fam(325)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IRIX fam service allows an attacker to obtain a list of all files on the server.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0059', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0059', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:35:57.570Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2003-1567 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | none | yes | partial | 2.0.3 | 2026-05-28 21:23:10.554802+03:00 | ['CWE-200'] | ['https://www.aqtronix.com/Advisories/AQ-2003-02.txt'] | 2026-05-28 21:23:03.291000+03:00 | a7034f6b512f1e06e71f68491e6d86539fb1c33b4e15b13b7e51c29f00c31982 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html', 'name': '20031227 AQ-2003-02: Microsoft IIS Logging Failure', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/288308', 'name': 'VU#288308', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/5648', 'name': '5648', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:35:17.592Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2003-1567', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T18:23:10.554802Z'}}}], 'references': [{'url': 'https://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'tags': ['exploit']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T18:23:03.291Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html', 'name': '20031227 AQ-2003-02: Microsoft IIS Logging Failure', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ']}, {'url': 'http://www.kb.cert.org/vuls/id/288308', 'name': 'VU#288308', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/5648', 'name': '5648', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2009-01-15T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html', 'name': '20031227 AQ-2003-02: Microsoft IIS Logging Failure', 'refsource': 'NTBUGTRAQ'}, {'url': 'http://www.kb.cert.org/vuls/id/288308', 'name': 'VU#288308', 'refsource': 'CERT-VN'}, {'url': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'name': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/5648', 'name': '5648', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2003-1567', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2003-1567', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T18:23:16.713Z', 'dateReserved': '2009-01-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2009-01-15T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} |
CVE-1999-1413 | none | no | partial | 2.0.3 | 2024-08-01 22:40:04.144434+03:00 | 2024-08-01 22:40:10.351000+03:00 | 40c991b92da1366aa770004690214c5163909b349e9d7a67ede933f869770edc | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=87602167419549&w=2', 'name': '19960803 Exploiting Zolaris 2.4 ?? :)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/296', 'name': '296', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T17:11:03.182Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-1413', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:40:04.144434Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:40:10.351Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '1996-08-03T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=87602167419549&w=2', 'name': '19960803 Exploiting Zolaris 2.4 ?? :)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/296', 'name': '296', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T13:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=87602167419549&w=2', 'name': '19960803 Exploiting Zolaris 2.4 ?? :)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/296', 'name': '296', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-1413', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-1413', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T19:40:14.542Z', 'dateReserved': '2001-08-31T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-09-12T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-1999-0159 | 3.50 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L | none | no | partial | 2.0.3 | 2025-08-27 21:38:07.688027+03:00 | ['CWE-400'] | 2025-08-27 20:45:45.182000+03:00 | 71d084ad09c6526ce559de969bc896ff19a263eb1a29d5481ef1f6d7e746ac8c | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.802Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.5, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0159', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-08-27T18:38:07.688027Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-08-27T17:45:45.182Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:49:36.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0159', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0159', 'state': 'PUBLISHED', 'dateUpdated': '2025-08-27T18:38:54.613Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-10003 | none | no | partial | 2.0.3 | 2024-10-17 19:12:56.245378+03:00 | 2024-10-17 19:13:02.642000+03:00 | 21a1f135b2dfd00a8fcfef79fa57f79402e86d0e375bfddbf273c704a8b8ecca | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-10003', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-10-17T16:12:56.245378Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-17T16:13:02.642Z'}}], 'cna': {'tags': ['unsupported-when-assigned'], 'title': 'mikexstudios Xcomic os command injection', 'metrics': [{'cvssV4_0': {'version': '4.0', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}}, {'cvssV3_1': {'version': '3.1', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}}, {'cvssV3_0': {'version': '3.0', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}}, {'cvssV2_0': {'version': '2.0', 'baseScore': 5.1, 'vectorString': 'AV:N/AC:H/Au:N/C:P/I:P/A:P'}}], 'affected': [{'vendor': 'mikexstudios', 'product': 'Xcomic', 'versions': [{'status': 'affected', 'version': '0.8.0'}, {'status': 'affected', 'version': '0.8.1'}, {'status': 'affected', 'version': '0.8.2'}]}], 'timeline': [{'lang': 'en', 'time': '2005-07-20T00:00:00.000Z', 'value': 'Advisory disclosed'}, {'lang': 'en', 'time': '2005-07-22T00:00:00.000Z', 'value': 'Countermeasure disclosed'}, {'lang': 'en', 'time': '2024-10-15T02:00:00.000Z', 'value': 'VulDB entry created'}, {'lang': 'en', 'time': '2024-10-15T11:55:54.000Z', 'value': 'VulDB entry last update'}], 'references': [{'url': 'https://vuldb.com/?id.280359', 'name': 'VDB-280359 | mikexstudios Xcomic os command injection', 'tags': ['vdb-entry', 'technical-description']}, {'url': 'https://vuldb.com/?ctiid.280359', 'name': 'VDB-280359 | CTI Indicators (IOB, IOC, TTP, IOA)', 'tags': ['signature', 'permissions-required']}, {'url': 'http://xcomic.mikexstudios.com/forum/viewtopic.php?id=130', 'tags': ['broken-link', 'exploit']}, {'url': 'https://github.com/mikexstudios/xcomic/commit/6ed8e3cc336e29f09c7e791863d0559939da98bf', 'tags': ['patch']}, {'url': 'https://github.com/mikexstudios/xcomic/releases/tag/v0.8.3', 'tags': ['patch']}, {'url': 'https://web.archive.org/web/20071218144304/http://xcomic.mikexstudios.com/forum/viewtopic.php?id=130', 'tags': ['related']}], 'descriptions': [{'lang': 'en', 'value': 'A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.3 is able to address this issue. The patch is named 6ed8e3cc336e29f09c7e791863d0559939da98bf. It is recommended to upgrade the affected component.'}, {'lang': 'de', 'value': 'Es wurde eine Schwachstelle in mikexstudios Xcomic bis 0.8.2 entdeckt. Sie wurde als kritisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf. Mit der Manipulation des Arguments cmd mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Die Komplexität eines Angriffs ist eher hoch. Sie ist schwierig auszunutzen. Der Exploit steht zur öffentlichen Verfügung. Ein Aktualisieren auf die Version 0.8.3 vermag dieses Problem zu lösen. Der Patch wird als 6ed8e3cc336e29f09c7e791863d0559939da98bf bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': 'OS Command Injection'}]}], 'providerMetadata': {'orgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'shortName': 'VulDB', 'dateUpdated': '2024-10-17T14:00:16.571Z'}}}, 'cveMetadata': {'cveId': 'CVE-2005-10003', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-17T16:13:06.608Z', 'dateReserved': '2024-10-15T09:49:35.446Z', 'assignerOrgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'datePublished': '2024-10-17T14:00:16.571Z', 'assignerShortName': 'VulDB'}, 'dataVersion': '5.1'} | ||||
CVE-2004-2154 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-07-16 17:59:33.852643+03:00 | ['CWE-178'] | 2024-07-16 18:00:32.347000+03:00 | 726192eb7b80a355ea5495b02b4400205e84c8712b121f74db67c782dc010a20 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2005_18_sr.html', 'name': 'SUSE-SR:2005:018', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.cups.org/str.php?L700', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-571.html', 'name': 'RHSA-2005:571', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274', 'name': 'FLSA:163274', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-185-1', 'name': 'USN-185-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9940', 'name': 'oval:org.mitre.oval:def:9940', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:15:01.684Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2154', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-07-16T14:59:33.852643Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:apple:cups:-:*:*:*:*:*:*:*'], 'vendor': 'apple', 'product': 'cups', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '1.1.21', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:canonical:ubuntu_linux:4.10:*:*:*:*:*:*:*'], 'vendor': 'canonical', 'product': 'ubuntu_linux', 'versions': [{'status': 'affected', 'version': '4.10'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-178', 'description': 'CWE-178 Improper Handling of Case Sensitivity'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-07-16T15:00:32.347Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-05-13T00:00:00.000Z', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2005_18_sr.html', 'name': 'SUSE-SR:2005:018', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.cups.org/str.php?L700', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-571.html', 'name': 'RHSA-2005:571', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274', 'name': 'FLSA:163274', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.ubuntu.com/usn/usn-185-1', 'name': 'USN-185-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9940', 'name': 'oval:org.mitre.oval:def:9940', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2017-10-10T00:57:01.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2004-2154', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-08T01:15:01.684Z', 'dateReserved': '2005-07-05T00:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2005-07-05T04:00:00.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'} | |
CVE-2001-1125 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-02-08 20:21:18.892262+03:00 | ['CWE-494'] | 2025-01-16 20:03:58.429000+03:00 | 3fc20a10f8baf35ecdb04e49aeed86c6279ac39269e172acfa1f86fe01349d86 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/218717', 'name': '20011005 Symantec LiveUpdate attacks', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/3403', 'name': '3403', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7235', 'name': 'liveupdate-host-verification(7235)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:44:07.831Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-1125', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-08T17:21:18.892262Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-494', 'description': 'CWE-494 Download of Code Without Integrity Check'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:03:58.429Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-10-05T04:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/218717', 'name': '20011005 Symantec LiveUpdate attacks', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/3403', 'name': '3403', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7235', 'name': 'liveupdate-host-verification(7235)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-12-19T02:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/218717', 'name': '20011005 Symantec LiveUpdate attacks', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/3403', 'name': '3403', 'refsource': 'BID'}, {'url': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'name': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'refsource': 'CONFIRM'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7235', 'name': 'liveupdate-host-verification(7235)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-1125', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-1125', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:04:41.599Z', 'dateReserved': '2002-03-15T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-03-15T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2001-0827 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2025-04-23 16:47:02.079015+03:00 | ['CWE-400'] | 2025-04-23 18:37:32.655000+03:00 | 115bb2704b929a6028a9a4684df64dab522222de729249dfaf358a3e63ca229e | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html', 'name': '20010704 CesarFTPd, Cerberus FTPd', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/2976', 'name': '2976', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:37:06.984Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0827', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-23T13:47:02.079015Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-23T15:37:32.655Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-07-04T00:00:00.000Z', 'references': [{'url': 'http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html', 'name': '20010704 CesarFTPd, Cerberus FTPd', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/2976', 'name': '2976', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2001-11-28T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html', 'name': '20010704 CesarFTPd, Cerberus FTPd', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/2976', 'name': '2976', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0827', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0827', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-23T15:37:38.404Z', 'dateReserved': '2001-11-22T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-11-22T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-0210 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | active | no | total | 2.0.3 | 2025-02-07 17:32:41.753543+03:00 | ['CWE-120'] | 2025-02-07 17:33:00.465000+03:00 | 0338c0f3a54dc3d8994f35b0b21212d45aa56c89330f225030bc423e7fb87c54 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.us-cert.gov/cas/techalerts/TA04-196A.html', 'name': 'TA04-196A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/647436', 'name': 'VU#647436', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166', 'name': 'oval:org.mitre.oval:def:2166', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020', 'name': 'MS04-020', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847', 'name': 'oval:org.mitre.oval:def:2847', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16590', 'name': 'win-posix-bo(16590)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:10:03.856Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0210', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:32:41.753543Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-03-03', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210'}}}], 'timeline': [{'lang': 'en', 'time': '2022-03-03T00:00:00.000Z', 'value': 'CVE-2004-0210 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-120', 'description': "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:33:00.465Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-07-13T00:00:00.000Z', 'references': [{'url': 'http://www.us-cert.gov/cas/techalerts/TA04-196A.html', 'name': 'TA04-196A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.kb.cert.org/vuls/id/647436', 'name': 'VU#647436', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166', 'name': 'oval:org.mitre.oval:def:2166', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020', 'name': 'MS04-020', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847', 'name': 'oval:org.mitre.oval:def:2847', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16590', 'name': 'win-posix-bo(16590)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-12T19:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.us-cert.gov/cas/techalerts/TA04-196A.html', 'name': 'TA04-196A', 'refsource': 'CERT'}, {'url': 'http://www.kb.cert.org/vuls/id/647436', 'name': 'VU#647436', 'refsource': 'CERT-VN'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166', 'name': 'oval:org.mitre.oval:def:2166', 'refsource': 'OVAL'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020', 'name': 'MS04-020', 'refsource': 'MS'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847', 'name': 'oval:org.mitre.oval:def:2847', 'refsource': 'OVAL'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16590', 'name': 'win-posix-bo(16590)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0210', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0210', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.314Z', 'dateReserved': '2004-03-11T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0013 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | partial | 2.0.3 | 2024-08-01 21:59:12.970313+03:00 | ['CWE-522'] | 2024-08-01 22:02:37.469000+03:00 | ef8575e177eda91d123be885ec6d465ce8a8d851f08dbe79d9cff8c68ca4cc10 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.463Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0013', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T18:59:12.970313Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*'], 'vendor': 'ssh', 'product': 'ssh', 'versions': [{'status': 'affected', 'version': '1.2.0'}, {'status': 'affected', 'version': '1.2.1'}, {'status': 'affected', 'version': '1.2.2'}, {'status': 'affected', 'version': '1.2.3'}, {'status': 'affected', 'version': '1.2.4'}, {'status': 'affected', 'version': '1.2.5'}, {'status': 'affected', 'version': '1.2.6'}, {'status': 'affected', 'version': '1.2.7'}, {'status': 'affected', 'version': '1.2.8'}, {'status': 'affected', 'version': '1.2.9'}, {'status': 'affected', 'version': '1.2.10'}, {'status': 'affected', 'version': '1.2.11'}, {'status': 'affected', 'version': '1.2.12'}, {'status': 'affected', 'version': '1.2.13'}, {'status': 'affected', 'version': '1.2.14'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-522', 'description': 'CWE-522 Insufficiently Protected Credentials'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:02:37.469Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:24:59.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0013', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0013', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T19:02:44.132Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0039 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | partial | 2.0.3 | 2024-09-04 18:36:17.863572+03:00 | ['CWE-77'] | 2024-09-04 18:21:04.306000+03:00 | 554f2a8182ae670c1caee150cbda20ec7cd7b2f5230f70c230e44a1343332294 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX', 'name': '19970501-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/333', 'name': 'http-sgi-webdist(333)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.cert.org/advisories/CA-1997-12.html', 'name': 'CA-1997-12', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/374', 'name': '374', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.osvdb.org/235', 'name': '235', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.773Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0039', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-09-04T15:36:17.863572Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:-:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '0'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-77', 'description': "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-09-04T15:21:04.306Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX', 'name': '19970501-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/333', 'name': 'http-sgi-webdist(333)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.cert.org/advisories/CA-1997-12.html', 'name': 'CA-1997-12', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.securityfocus.com/bid/374', 'name': '374', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.osvdb.org/235', 'name': '235', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX', 'name': '19970501-02-PX', 'refsource': 'SGI'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/333', 'name': 'http-sgi-webdist(333)', 'refsource': 'XF'}, {'url': 'http://www.cert.org/advisories/CA-1997-12.html', 'name': 'CA-1997-12', 'refsource': 'CERT'}, {'url': 'http://www.securityfocus.com/bid/374', 'name': '374', 'refsource': 'BID'}, {'url': 'http://www.osvdb.org/235', 'name': '235', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0039', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0039', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-12T14:37:05.701Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2003-0063 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | partial | 2.0.3 | 2024-07-24 20:38:21.119752+03:00 | 2024-07-24 20:39:25.055000+03:00 | a66a1e61c9f2455f46706b2dedcec31091149163e4f9506f00192de16e4afcc6 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.debian.org/security/2003/dsa-380', 'name': 'DSA-380', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-067.html', 'name': 'RHSA-2003:067', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-066.html', 'name': 'RHSA-2003:066', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=104612710031920&w=2', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-064.html', 'name': 'RHSA-2003:064', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-065.html', 'name': 'RHSA-2003:065', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/6940', 'name': '6940', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/11414.php', 'name': 'terminal-emulator-window-title(11414)', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2024/06/15/1', 'name': '[oss-security] 20240615 iTerm2 3.5.x title reporting bug', 'tags': ['mailing-list', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:43:35.241Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2003-0063', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-07-24T17:38:21.119752Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:xfree86:xfree86:*:*:*:*:*:*:*:*'], 'vendor': 'xfree86', 'product': 'xfree86', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '4.2.0'}], 'defaultStatus': 'unknown'}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-07-24T17:39:25.055Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2003-02-24T05:00:00.000Z', 'references': [{'url': 'http://www.debian.org/security/2003/dsa-380', 'name': 'DSA-380', 'tags': ['vendor-advisory']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-067.html', 'name': 'RHSA-2003:067', 'tags': ['vendor-advisory']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-066.html', 'name': 'RHSA-2003:066', 'tags': ['vendor-advisory']}, {'url': 'http://marc.info/?l=bugtraq&m=104612710031920&w=2', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-064.html', 'name': 'RHSA-2003:064', 'tags': ['vendor-advisory']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-065.html', 'name': 'RHSA-2003:065', 'tags': ['vendor-advisory']}, {'url': 'http://www.securityfocus.com/bid/6940', 'name': '6940', 'tags': ['vdb-entry']}, {'url': 'http://www.iss.net/security_center/static/11414.php', 'name': 'terminal-emulator-window-title(11414)', 'tags': ['vdb-entry']}, {'url': 'http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list']}, {'url': 'http://www.openwall.com/lists/oss-security/2024/06/15/1', 'name': '[oss-security] 20240615 iTerm2 3.5.x title reporting bug', 'tags': ['mailing-list']}], 'descriptions': [{'lang': 'en', 'value': "The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2024-06-15T14:05:53.568Z'}}}, 'cveMetadata': {'cveId': 'CVE-2003-0063', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:05:49.769Z', 'dateReserved': '2003-02-04T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-01T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2002-1372 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2024-01-25 18:24:01.752587+03:00 | ['CWE-252'] | 2025-01-16 20:42:04.551000+03:00 | f1eaff9c92017ddc38e1804ec8cc8feea966abbb6f0a18fe2674a50e22369028 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_VULNWATCH', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702', 'name': 'CLSA-2003:702', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'http://www.debian.org/security/2003/dsa-232', 'name': 'DSA-232', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2003_002_cups.html', 'name': 'SuSE-SA:2003:002', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.idefense.com/advisory/12.19.02.txt', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-295.html', 'name': 'RHSA-2002:295', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=104032149026670&w=2', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001', 'name': 'MDKSA-2003:001', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/6440', 'name': '6440', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/10912', 'name': 'cups-file-descriptor-dos(10912)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:19:28.771Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1372', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-25T15:24:01.752587Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-252', 'description': 'CWE-252 Unchecked Return Value'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:42:04.551Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-12-19T05:00:00.000Z', 'references': [{'url': 'http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_VULNWATCH']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702', 'name': 'CLSA-2003:702', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'http://www.debian.org/security/2003/dsa-232', 'name': 'DSA-232', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.novell.com/linux/security/advisories/2003_002_cups.html', 'name': 'SuSE-SA:2003:002', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.idefense.com/advisory/12.19.02.txt', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-295.html', 'name': 'RHSA-2002:295', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://marc.info/?l=bugtraq&m=104032149026670&w=2', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001', 'name': 'MDKSA-2003:001', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://www.securityfocus.com/bid/6440', 'name': '6440', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/10912', 'name': 'cups-file-descriptor-dos(10912)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2007-12-20T05:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'refsource': 'VULNWATCH'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702', 'name': 'CLSA-2003:702', 'refsource': 'CONECTIVA'}, {'url': 'http://www.debian.org/security/2003/dsa-232', 'name': 'DSA-232', 'refsource': 'DEBIAN'}, {'url': 'http://www.novell.com/linux/security/advisories/2003_002_cups.html', 'name': 'SuSE-SA:2003:002', 'refsource': 'SUSE'}, {'url': 'http://www.idefense.com/advisory/12.19.02.txt', 'name': 'http://www.idefense.com/advisory/12.19.02.txt', 'refsource': 'MISC'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-295.html', 'name': 'RHSA-2002:295', 'refsource': 'REDHAT'}, {'url': 'http://marc.info/?l=bugtraq&m=104032149026670&w=2', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001', 'name': 'MDKSA-2003:001', 'refsource': 'MANDRAKE'}, {'url': 'http://www.securityfocus.com/bid/6440', 'name': '6440', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/10912', 'name': 'cups-file-descriptor-dos(10912)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1372', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1372', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:42:09.355Z', 'dateReserved': '2002-12-16T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-01T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-3274 | none | no | partial | 2.0.3 | 2024-04-02 21:26:04.388396+03:00 | 2024-10-15 17:14:56.457000+03:00 | ade63bd58c2065b863b04acf4a765d9620d4b2f38b11da3f28c92aaf4a51509b | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:235', 'name': 'MDKSA-2005:235', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18684', 'name': '18684', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18977', 'name': '18977', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:220', 'name': 'MDKSA-2005:220', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044', 'name': 'MDKSA-2006:044', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/15528', 'name': '15528', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/427981/100/0/threaded', 'name': 'FLSA:157459-4', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/219-1/', 'name': 'USN-219-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0190.html', 'name': 'RHSA-2006:0190', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:218', 'name': 'MDKSA-2005:218', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17826', 'name': '17826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://lkml.org/lkml/2005/6/23/249', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://lkml.org/lkml/2005/6/24/173', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723', 'name': 'oval:org.mitre.oval:def:11723', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-663.html', 'name': 'RHSA-2005:663', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:219', 'name': 'MDKSA-2005:219', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:10:07.282Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3274', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-02T18:26:04.388396Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-15T14:14:56.457Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-07-26T00:00:00.000Z', 'references': [{'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:235', 'name': 'MDKSA-2005:235', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA']}, {'url': 'http://secunia.com/advisories/18684', 'name': '18684', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/18977', 'name': '18977', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:220', 'name': 'MDKSA-2005:220', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044', 'name': 'MDKSA-2006:044', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA']}, {'url': 'http://www.securityfocus.com/bid/15528', 'name': '15528', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.securityfocus.com/archive/1/427981/100/0/threaded', 'name': 'FLSA:157459-4', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://usn.ubuntu.com/219-1/', 'name': 'USN-219-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0190.html', 'name': 'RHSA-2006:0190', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:218', 'name': 'MDKSA-2005:218', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://secunia.com/advisories/17826', 'name': '17826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://lkml.org/lkml/2005/6/23/249', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://lkml.org/lkml/2005/6/24/173', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723', 'name': 'oval:org.mitre.oval:def:11723', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-663.html', 'name': 'RHSA-2005:663', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:219', 'name': 'MDKSA-2005:219', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}], 'descriptions': [{'lang': 'en', 'value': 'Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:235', 'name': 'MDKSA-2005:235', 'refsource': 'MANDRIVA'}, {'url': 'http://secunia.com/advisories/18684', 'name': '18684', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/18977', 'name': '18977', 'refsource': 'SECUNIA'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:220', 'name': 'MDKSA-2005:220', 'refsource': 'MANDRAKE'}, {'url': 'http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044', 'name': 'MDKSA-2006:044', 'refsource': 'MANDRIVA'}, {'url': 'http://www.securityfocus.com/bid/15528', 'name': '15528', 'refsource': 'BID'}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'refsource': 'DEBIAN'}, {'url': 'http://www.securityfocus.com/archive/1/427981/100/0/threaded', 'name': 'FLSA:157459-4', 'refsource': 'FEDORA'}, {'url': 'https://usn.ubuntu.com/219-1/', 'name': 'USN-219-1', 'refsource': 'UBUNTU'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0190.html', 'name': 'RHSA-2006:0190', 'refsource': 'REDHAT'}, {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'refsource': 'CONFIRM'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:218', 'name': 'MDKSA-2005:218', 'refsource': 'MANDRAKE'}, {'url': 'http://secunia.com/advisories/17826', 'name': '17826', 'refsource': 'SECUNIA'}, {'url': 'http://lkml.org/lkml/2005/6/23/249', 'name': 'http://lkml.org/lkml/2005/6/23/249', 'refsource': 'CONFIRM'}, {'url': 'http://lkml.org/lkml/2005/6/24/173', 'name': 'http://lkml.org/lkml/2005/6/24/173', 'refsource': 'CONFIRM'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723', 'name': 'oval:org.mitre.oval:def:11723', 'refsource': 'OVAL'}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'refsource': 'FEDORA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-663.html', 'name': 'RHSA-2005:663', 'refsource': 'REDHAT'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:219', 'name': 'MDKSA-2005:219', 'refsource': 'MANDRAKE'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3274', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3274', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-15T14:15:02.658Z', 'dateReserved': '2005-10-20T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-10-20T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-2005-4650 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | none | yes | partial | 2.0.3 | 2025-01-16 22:56:15.505761+03:00 | ['CWE-770'] | 2025-01-16 22:56:05.410000+03:00 | 64426efdf8b70ffbbe19fb28855e2d9917b930f33c07bfa23fba627efe219d76 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/21041', 'name': '21041', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.joomla.org/content/view/499/66/', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17675', 'name': '17675', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:53:28.563Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4650', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:56:15.505761Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-770', 'description': 'CWE-770 Allocation of Resources Without Limits or Throttling'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:56:05.410Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/21041', 'name': '21041', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.joomla.org/content/view/499/66/', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://secunia.com/advisories/17675', 'name': '17675', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}], 'descriptions': [{'lang': 'en', 'value': 'Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-01-14T01:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/21041', 'name': '21041', 'refsource': 'OSVDB'}, {'url': 'http://www.joomla.org/content/view/499/66/', 'name': 'http://www.joomla.org/content/view/499/66/', 'refsource': 'CONFIRM'}, {'url': 'http://secunia.com/advisories/17675', 'name': '17675', 'refsource': 'SECUNIA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4650', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4650', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:56:20.937Z', 'dateReserved': '2006-01-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-01-14T01:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2000-1245 | none | no | partial | 2.0.3 | 2024-08-29 18:37:49.712788+03:00 | 2024-08-29 18:38:36.769000+03:00 | 8ef725c2d84d675c1e5dd18ef39454afd040d45aa7049c43b6046e33b8f7f82f | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T05:53:28.406Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2000-1245', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-29T15:37:49.712788Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-29T15:38:36.769Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2010-04-05T15:15:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'name': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2000-1245', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2000-1245', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-17T00:05:49.841Z', 'dateReserved': '2010-04-05T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2010-04-05T15:15:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-2001-0331 | none | yes | partial | 2.0.3 | 2024-08-29 18:50:47.972234+03:00 | 2024-08-29 18:50:53.304000+03:00 | 53fba33dee04e44948f8bb4238bf921db3f4afca4076f9f396838279f680393d | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/1822', 'name': '1822', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/258632', 'name': 'VU#258632', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6502', 'name': 'irix-espd-bo(6502)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P', 'name': '20010501-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://xforce.iss.net/alerts/advise76.php', 'name': '20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure', 'tags': ['third-party-advisory', 'x_refsource_ISS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/2714', 'name': '2714', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T16:21:19.150Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0331', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-29T15:50:47.972234Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-29T15:50:53.304Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-05-09T00:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/1822', 'name': '1822', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.kb.cert.org/vuls/id/258632', 'name': 'VU#258632', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6502', 'name': 'irix-espd-bo(6502)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P', 'name': '20010501-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://xforce.iss.net/alerts/advise76.php', 'name': '20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure', 'tags': ['third-party-advisory', 'x_refsource_ISS']}, {'url': 'http://www.securityfocus.com/bid/2714', 'name': '2714', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2024-08-08T16:14:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/1822', 'name': '1822', 'refsource': 'OSVDB'}, {'url': 'http://www.kb.cert.org/vuls/id/258632', 'name': 'VU#258632', 'refsource': 'CERT-VN'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6502', 'name': 'irix-espd-bo(6502)', 'refsource': 'XF'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P', 'name': '20010501-01-P', 'refsource': 'SGI'}, {'url': 'http://xforce.iss.net/alerts/advise76.php', 'name': '20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure', 'refsource': 'ISS'}, {'url': 'http://www.securityfocus.com/bid/2714', 'name': '2714', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0331', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0331', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-29T15:50:57.052Z', 'dateReserved': '2001-05-08T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-09-18T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||||
CVE-1999-0029 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-08-01 22:28:25.242481+03:00 | ['CWE-125'] | 2024-08-01 22:31:28.822000+03:00 | 9a6a1ef2a2a0920aa052dcc1ebc1b08b956a8aa9a46712518aaac9b3a6718964 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.695Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0029', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:28:25.242481Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:5.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:xfs:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.4:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:31:28.822Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'root privileges via buffer overflow in ordist command on SGI IRIX systems.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:27:27.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'root privileges via buffer overflow in ordist command on SGI IRIX systems.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0029', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0029', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:07:56.381Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0043 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-08-01 22:56:17.928328+03:00 | ['CWE-78'] | 2024-08-01 23:02:42.640000+03:00 | 0572e979b7462ee246e65d6335bdea2ebdf7709d31ca1d8e8a877e8a19d2adbd | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.295Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0043', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:56:17.928328Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:isc:inn:1.4sec:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.4sec2:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.4unoff3:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.4unoff4:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.5:*:*:*:*:*:*:*'], 'vendor': 'isc', 'product': 'inn', 'versions': [{'status': 'affected', 'version': '1.4sec'}, {'status': 'affected', 'version': '1.4sec2'}, {'status': 'affected', 'version': '1.4unoff3'}, {'status': 'affected', 'version': '1.4unoff4'}, {'status': 'affected', 'version': '1.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:a:netscape:news_server:1.1:*:*:*:*:*:*:*'], 'vendor': 'netscape', 'product': 'news_server', 'versions': [{'status': 'affected', 'version': '1.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:bsdi:bsd_os:2.1:*:*:*:*:*:*:*'], 'vendor': 'bsdi', 'product': 'bsd_os', 'versions': [{'status': 'affected', 'version': '2.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:caldera:openlinux:1.0:*:*:*:*:*:*:*'], 'vendor': 'caldera', 'product': 'openlinux', 'versions': [{'status': 'affected', 'version': '1.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:redhat:linux:4.0:*:*:*:*:*:*:*'], 'vendor': 'redhat', 'product': 'linux', 'versions': [{'status': 'affected', 'version': '4.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:redhat:linux:4.1:*:*:*:*:*:*:*'], 'vendor': 'redhat', 'product': 'linux', 'versions': [{'status': 'affected', 'version': '4.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:h:nec:goah_intrasv:1.1:*:*:*:*:*:*:*'], 'vendor': 'nec', 'product': 'goah_intrasv', 'versions': [{'status': 'affected', 'version': '1.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:h:nec:goah_networksv:1.2:*:*:*:*:*:*:*', 'cpe:2.3:h:nec:goah_networksv:2.2:*:*:*:*:*:*:*', 'cpe:2.3:h:nec:goah_networksv:3.1:*:*:*:*:*:*:*'], 'vendor': 'nec', 'product': 'goah_networksv', 'versions': [{'status': 'affected', 'version': '1.2'}, {'status': 'affected', 'version': '2.2'}, {'status': 'affected', 'version': '3.1'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:02:42.640Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:31:06.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0043', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0043', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:03:35.981Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-10001 | none | no | partial | 2.0.3 | 2025-04-14 20:15:38.326553+03:00 | 2025-04-14 20:15:39.774000+03:00 | 082521f0f602e038522d33fbf0c2b9d1ee039f4b09351a12324e0a46245453ab | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://vuldb.com/?id.1022', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:23.500Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-10001', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-14T17:15:38.326553Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-14T17:15:39.774Z'}}], 'cna': {'tags': ['unsupported-when-assigned'], 'title': 'Netegrity SiteMinder Login smpwservicescgi.exe redirect', 'credits': [{'lang': 'en', 'value': 'Marc Ruef'}], 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}], 'affected': [{'vendor': 'Netegrity', 'product': 'SiteMinder', 'versions': [{'status': 'affected', 'version': '4.5.0'}, {'status': 'affected', 'version': '4.5.1'}]}], 'references': [{'url': 'https://vuldb.com/?id.1022', 'tags': ['x_refsource_MISC']}], 'x_generator': 'vuldb.com', 'descriptions': [{'lang': 'en', 'value': 'A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-601', 'description': 'CWE-601 Open Redirect'}]}], 'providerMetadata': {'orgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'shortName': 'VulDB', 'dateUpdated': '2022-03-28T20:45:47.000Z'}, 'x_legacyV4Record': {'credit': 'Marc Ruef', 'impact': {'cvss': {'version': '3.1', 'baseScore': '5.4', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '4.5.0'}, {'version_value': '4.5.1'}]}, 'product_name': 'SiteMinder'}]}, 'vendor_name': 'Netegrity'}]}}, 'data_type': 'CVE', 'generator': 'vuldb.com', 'references': {'reference_data': [{'url': 'https://vuldb.com/?id.1022', 'name': 'https://vuldb.com/?id.1022', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-601 Open Redirect'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-10001', 'STATE': 'PUBLIC', 'TITLE': 'Netegrity SiteMinder Login smpwservicescgi.exe redirect', 'ASSIGNER': 'cna@vuldb.com', 'REQUESTER': 'cna@vuldb.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-10001', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-15T14:45:26.644Z', 'dateReserved': '2022-01-28T00:00:00.000Z', 'assignerOrgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'datePublished': '2022-03-28T20:45:47.000Z', 'assignerShortName': 'VulDB'}, 'dataVersion': '5.1'} | ||||
CVE-2004-1901 | 5.50 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N | none | no | partial | 2.0.3 | 2024-01-31 18:42:15.161093+03:00 | ['CWE-59'] | 2025-01-16 21:09:20.441000+03:00 | 59a908b65a90e96efac7c0b926b3418e0ac8dbf22021abd27f365d5c45151c04 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/10060', 'name': '10060', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://security.gentoo.org/glsa/glsa-200404-01.xml', 'name': 'GLSA-200404-01', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'http://secunia.com/advisories/11305', 'name': '11305', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15754', 'name': 'portage-lockfile-hardlink(15754)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:07:49.064Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-1901', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-31T15:42:15.161093Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-59', 'description': "CWE-59 Improper Link Resolution Before File Access ('Link Following')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:09:20.441Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-04-06T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/10060', 'name': '10060', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://security.gentoo.org/glsa/glsa-200404-01.xml', 'name': 'GLSA-200404-01', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'http://secunia.com/advisories/11305', 'name': '11305', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15754', 'name': 'portage-lockfile-hardlink(15754)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/10060', 'name': '10060', 'refsource': 'BID'}, {'url': 'http://security.gentoo.org/glsa/glsa-200404-01.xml', 'name': 'GLSA-200404-01', 'refsource': 'GENTOO'}, {'url': 'http://secunia.com/advisories/11305', 'name': '11305', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15754', 'name': 'portage-lockfile-hardlink(15754)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-1901', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-1901', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:09:40.758Z', 'dateReserved': '2005-05-04T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-05-10T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2002-0367 | 7.80 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | active | no | total | 2.0.3 | 2025-02-07 17:33:43.942338+03:00 | ['CWE-269'] | 2025-02-07 17:33:33.461000+03:00 | 6f6ff763c6ec8f5ac97227b50875bebe466261e4a53155718c4d7d9309b3d090 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/264441', 'name': '20020326 Re: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=ntbugtraq&m=101614320402695&w=2', 'name': '20020314 DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/4287', 'name': '4287', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024', 'name': 'MS02-024', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/264927', 'name': '20020327 Local Security Vulnerability in Windows NT and Windows 2000', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76', 'name': 'oval:org.mitre.oval:def:76', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/262074', 'name': '20020314 Fwd: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/8462.php', 'name': 'win-debug-duplicate-handles(8462)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158', 'name': 'oval:org.mitre.oval:def:158', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:49:28.090Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0367', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:33:43.942338Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-03-03', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367'}}}], 'timeline': [{'lang': 'en', 'time': '2022-03-03T00:00:00.000Z', 'value': 'CVE-2002-0367 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-269', 'description': 'CWE-269 Improper Privilege Management'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:33:33.461Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-03-14T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/264441', 'name': '20020326 Re: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=ntbugtraq&m=101614320402695&w=2', 'name': '20020314 DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/4287', 'name': '4287', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024', 'name': 'MS02-024', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.securityfocus.com/archive/1/264927', 'name': '20020327 Local Security Vulnerability in Windows NT and Windows 2000', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76', 'name': 'oval:org.mitre.oval:def:76', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/archive/1/262074', 'name': '20020314 Fwd: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.iss.net/security_center/static/8462.php', 'name': 'win-debug-duplicate-handles(8462)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158', 'name': 'oval:org.mitre.oval:def:158', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}], 'descriptions': [{'lang': 'en', 'value': 'smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2002-06-11T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/264441', 'name': '20020326 Re: DebPloit (exploit)', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=ntbugtraq&m=101614320402695&w=2', 'name': '20020314 DebPloit (exploit)', 'refsource': 'NTBUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/4287', 'name': '4287', 'refsource': 'BID'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024', 'name': 'MS02-024', 'refsource': 'MS'}, {'url': 'http://www.securityfocus.com/archive/1/264927', 'name': '20020327 Local Security Vulnerability in Windows NT and Windows 2000', 'refsource': 'BUGTRAQ'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76', 'name': 'oval:org.mitre.oval:def:76', 'refsource': 'OVAL'}, {'url': 'http://www.securityfocus.com/archive/1/262074', 'name': '20020314 Fwd: DebPloit (exploit)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.iss.net/security_center/static/8462.php', 'name': 'win-debug-duplicate-handles(8462)', 'refsource': 'XF'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158', 'name': 'oval:org.mitre.oval:def:158', 'refsource': 'OVAL'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0367', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0367', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.464Z', 'dateReserved': '2002-05-08T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2003-04-02T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0066 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-08-01 23:49:31.626761+03:00 | 2024-08-01 23:50:25.247000+03:00 | dd5b75aa4b8c1600705185af6bf55f28a12eaf50a429382e32b45cbcdfbfd560 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/719', 'name': '719', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.424Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0066', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:49:31.626761Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:john_s._roberts:anyform:1.0:*:*:*:*:*:*:*', 'cpe:2.3:a:john_s._roberts:anyform:2.0:*:*:*:*:*:*:*'], 'vendor': 'john_s._roberts', 'product': 'anyform', 'versions': [{'status': 'affected', 'version': '1.0'}, {'status': 'affected', 'version': '2.0'}], 'defaultStatus': 'unknown'}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:50:25.247Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/bid/719', 'name': '719', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'AnyForm CGI remote execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/719', 'name': '719', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'AnyForm CGI remote execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0066', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0066', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:50:29.555Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2002-2024 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | none | yes | partial | 2.0.3 | 2024-08-08 17:02:22.048868+03:00 | ['CWE-219'] | 2024-08-08 17:06:31.744000+03:00 | d8fbcd1ee0abb01ca0f1e6e9309a82d3bf1a7a2d3fddf4cb49ef04281a7b05a0 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://bugs.horde.org/show_bug.cgi?id=916', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/4445', 'name': '4445', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/8768.php', 'name': 'imp-php-path-disclosure(8768)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:51:17.588Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-2024', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-08T14:02:22.048868Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:horde:imp:2.2.7:*:*:*:*:*:*:*'], 'vendor': 'horde', 'product': 'imp', 'versions': [{'status': 'affected', 'version': '2.2.7'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-219', 'description': 'CWE-219 Storage of File with Sensitive Data Under Web Root'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-08T14:06:31.744Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://bugs.horde.org/show_bug.cgi?id=916', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/4445', 'name': '4445', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.iss.net/security_center/static/8768.php', 'name': 'imp-php-path-disclosure(8768)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-14T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://bugs.horde.org/show_bug.cgi?id=916', 'name': 'http://bugs.horde.org/show_bug.cgi?id=916', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/4445', 'name': '4445', 'refsource': 'BID'}, {'url': 'http://www.iss.net/security_center/static/8768.php', 'name': 'imp-php-path-disclosure(8768)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-2024', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-2024', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T18:24:20.639Z', 'dateReserved': '2005-07-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-1999-0468 | 8.20 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N | none | no | partial | 2.0.3 | 2025-08-25 21:47:58.178455+03:00 | ['CWE-200'] | 2025-08-25 21:51:42.771000+03:00 | 9e13f42383a267d48544afb1f3bbdb038bd20776ea7c0f85ae2e95a51c509c9e | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012', 'name': 'MS99-012', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:41:45.411Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0468', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-08-25T18:47:58.178455Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-08-25T18:51:42.771Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012', 'name': 'MS99-012', 'tags': ['vendor-advisory', 'x_refsource_MS']}], 'descriptions': [{'lang': 'en', 'value': "Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012', 'name': 'MS99-012', 'refsource': 'MS'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0468', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0468', 'state': 'PUBLISHED', 'dateUpdated': '2025-08-25T18:51:48.046Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-2773 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | active | yes | total | 2.0.3 | 2025-02-07 17:28:10.470925+03:00 | ['CWE-77'] | 2025-02-07 17:28:03.285000+03:00 | df9ad05baad849ceedf98162c9d9a27d826f6b5fbcea35dccc2965197d17179e | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=112499121725662&w=2', 'name': '20050825 Portcullis Security Advisory 05-014 HP Openview Remote Command', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/21999', 'name': 'hp-openview-node-manager-command-execution(21999)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'HPSBMA01224', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/14662', 'name': '14662', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/16555/', 'name': '16555', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'SSRT051023', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:45:02.175Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-2773', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:28:10.470925Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-03-25', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773'}}}], 'timeline': [{'lang': 'en', 'time': '2022-03-25T00:00:00.000Z', 'value': 'CVE-2005-2773 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-77', 'description': "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:28:03.285Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-08-25T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=112499121725662&w=2', 'name': '20050825 Portcullis Security Advisory 05-014 HP Openview Remote Command', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/21999', 'name': 'hp-openview-node-manager-command-execution(21999)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'HPSBMA01224', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.securityfocus.com/bid/14662', 'name': '14662', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/16555/', 'name': '16555', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'SSRT051023', 'tags': ['vendor-advisory', 'x_refsource_HP']}], 'descriptions': [{'lang': 'en', 'value': 'HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=112499121725662&w=2', 'name': '20050825 Portcullis Security Advisory 05-014 HP Openview Remote Command', 'refsource': 'BUGTRAQ'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/21999', 'name': 'hp-openview-node-manager-command-execution(21999)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'HPSBMA01224', 'refsource': 'HP'}, {'url': 'http://www.securityfocus.com/bid/14662', 'name': '14662', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/16555/', 'name': '16555', 'refsource': 'SECUNIA'}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'SSRT051023', 'refsource': 'HP'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-2773', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-2773', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.013Z', 'dateReserved': '2005-09-02T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-09-02T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-3170 | 5.00 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L | none | no | partial | 2.0.3 | 2024-10-15 17:14:19.553033+03:00 | ['CWE-295'] | 2024-10-15 17:14:23.499000+03:00 | ab9f69c4726888fa320091ef33b863ce8865e0d13a8d34255ac90421b27e32a8 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://support.microsoft.com/kb/883639', 'name': '883639', 'tags': ['vendor-advisory', 'x_refsource_MSKB', 'x_transferred']}, {'url': 'http://support.microsoft.com/kb/900345', 'name': '900345', 'tags': ['vendor-advisory', 'x_refsource_MSKB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:01:58.781Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3170', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-10-15T14:14:19.553033Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-295', 'description': 'CWE-295 Improper Certificate Validation'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-15T14:14:23.499Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://support.microsoft.com/kb/883639', 'name': '883639', 'tags': ['vendor-advisory', 'x_refsource_MSKB']}, {'url': 'http://support.microsoft.com/kb/900345', 'name': '900345', 'tags': ['vendor-advisory', 'x_refsource_MSKB']}], 'descriptions': [{'lang': 'en', 'value': 'The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-10-06T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://support.microsoft.com/kb/883639', 'name': '883639', 'refsource': 'MSKB'}, {'url': 'http://support.microsoft.com/kb/900345', 'name': '900345', 'refsource': 'MSKB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3170', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3170', 'state': 'PUBLISHED', 'dateUpdated': '2024-12-05T20:28:56.956Z', 'dateReserved': '2005-10-06T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-10-06T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-3302 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | partial | 2.0.3 | 2025-01-16 22:46:14.945366+03:00 | ['CWE-94'] | 2025-01-16 22:46:04.151000+03:00 | 27de896e0a96b4e1e180d112a72ce1e5ce137a488f5f6d02a81204a85d009c74 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://secunia.com/advisories/19754', 'name': '19754', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/17663', 'name': '17663', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.debian.org/security/2006/dsa-1039', 'name': 'DSA-1039', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:10:07.636Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3302', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:46:14.945366Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:46:04.151Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-09-30T00:00:00.000Z', 'references': [{'url': 'http://secunia.com/advisories/19754', 'name': '19754', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securityfocus.com/bid/17663', 'name': '17663', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.debian.org/security/2006/dsa-1039', 'name': 'DSA-1039', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-04-26T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://secunia.com/advisories/19754', 'name': '19754', 'refsource': 'SECUNIA'}, {'url': 'http://www.securityfocus.com/bid/17663', 'name': '17663', 'refsource': 'BID'}, {'url': 'http://www.debian.org/security/2006/dsa-1039', 'name': 'DSA-1039', 'refsource': 'DEBIAN'}, {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'name': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3302', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3302', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:46:53.131Z', 'dateReserved': '2005-10-24T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-10-24T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-2103 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-02-06 00:54:23.938897+03:00 | ['CWE-131'] | 2025-01-16 22:43:38.293000+03:00 | 864080307acb559a00978394e7f84339b066204c371c3a5eb88f6a610578f4ca | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://gaim.sourceforge.net/security/?id=22', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/426078/100/0/threaded', 'name': 'FLSA:158543', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2005_19_sr.html', 'name': 'SUSE-SR:2005:019', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11477', 'name': 'oval:org.mitre.oval:def:11477', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/14531', 'name': '14531', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/168-1/', 'name': 'USN-168-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-627.html', 'name': 'RHSA-2005:627', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-589.html', 'name': 'RHSA-2005:589', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:15:37.427Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-2103', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-05T21:54:23.938897Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-131', 'description': 'CWE-131 Incorrect Calculation of Buffer Size'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:43:38.293Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-08-12T04:00:00.000Z', 'references': [{'url': 'http://gaim.sourceforge.net/security/?id=22', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/archive/1/426078/100/0/threaded', 'name': 'FLSA:158543', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.novell.com/linux/security/advisories/2005_19_sr.html', 'name': 'SUSE-SR:2005:019', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11477', 'name': 'oval:org.mitre.oval:def:11477', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/bid/14531', 'name': '14531', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://usn.ubuntu.com/168-1/', 'name': 'USN-168-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-627.html', 'name': 'RHSA-2005:627', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-589.html', 'name': 'RHSA-2005:589', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2018-10-19T18:57:01.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2005-2103', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:43:45.313Z', 'dateReserved': '2005-06-30T04:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2005-08-16T08:00:00.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'} | |
CVE-2005-1831 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2024-04-15 22:19:25.314836+03:00 | 2025-01-16 22:09:07.904000+03:00 | f33fc56ed2233725682a0aa78969870877f8ca05fee4d1522e5e57fea22d9a29 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html', 'name': '20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html', 'name': '20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111755694008928&w=2', 'name': '20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/20417', 'name': '20417', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:06:57.739Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1831', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-04-15T19:19:25.314836Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:09:07.904Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-05-31T04:00:00.000Z', 'references': [{'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html', 'name': '20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html', 'name': '20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=111755694008928&w=2', 'name': '20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/20417', 'name': '20417', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don\'t see how this could happen unless the user\'s actual password was empty.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html', 'name': '20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'refsource': 'BUGTRAQ'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html', 'name': '20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=111755694008928&w=2', 'name': '20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/20417', 'name': '20417', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don\'t see how this could happen unless the user\'s actual password was empty."'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1831', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1831', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:09:52.691Z', 'dateReserved': '2005-06-02T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-02T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2005-1688 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | none | yes | partial | 2.0.3 | 2025-01-16 21:41:43.843484+03:00 | ['CWE-425'] | 2025-01-16 21:43:38.674000+03:00 | ea51426a68f8f7f22c053332f11d9f48942a815134e6194ab96ac6c8d79d2f95 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=111661517716733&w=2', 'name': '20050520 [BuHa Security] Wordpress SQL-Injection', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:59:24.035Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1688', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T18:41:43.843484Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-425', 'description': "CWE-425 Direct Request ('Forced Browsing')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:43:38.674Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-05-20T04:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=111661517716733&w=2', 'name': '20050520 [BuHa Security] Wordpress SQL-Injection', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=111661517716733&w=2', 'name': '20050520 [BuHa Security] Wordpress SQL-Injection', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1688', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1688', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:43:51.233Z', 'dateReserved': '2005-05-20T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-05-25T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-1674 | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | none | no | partial | 2.0.3 | 2025-01-16 21:10:54.662454+03:00 | ['CWE-352'] | 2025-01-16 21:10:27.407000+03:00 | 6e3a386538bdca79a80abbbb706ceca7a7fdac3b11fd72eeab5bdb3c3d5fd204 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0', 'name': '20050517 Help Center Live Vulnerabilities', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:59:23.943Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1674', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T18:10:54.662454Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-352', 'description': 'CWE-352 Cross-Site Request Forgery (CSRF)'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:10:27.407Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0', 'name': '20050517 Help Center Live Vulnerabilities', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-05-19T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'name': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0', 'name': '20050517 Help Center Live Vulnerabilities', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1674', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1674', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:10:58.838Z', 'dateReserved': '2005-05-19T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-05-19T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2004-0079 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2024-01-08 19:21:54.985893+03:00 | ['CWE-476'] | 2025-01-16 20:31:06.392000+03:00 | 3cd140c66c643d8d153aaa1e75051ba13a5a229de5fc325d887ea87e56f9bcc0 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/9899', 'name': '9899', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html', 'name': 'FEDORA-2005-1042', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html', 'name': 'ESA-20040317-003', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=108403806509920&w=2', 'name': 'SSRT4717', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-121.html', 'name': 'RHSA-2004:121', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2004:023', 'name': 'MDKSA-2004:023', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621', 'name': 'oval:org.mitre.oval:def:2621', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834', 'name': 'CLA-2004:834', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt', 'name': 'SCOSA-2004.10', 'tags': ['vendor-advisory', 'x_refsource_SCO', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17381', 'name': '17381', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://fedoranews.org/updates/FEDORA-2004-095.shtml', 'name': 'FEDORA-2004-095', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779', 'name': 'oval:org.mitre.oval:def:9779', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975', 'name': 'oval:org.mitre.oval:def:975', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524', 'name': '57524', 'tags': ['vendor-advisory', 'x_refsource_SUNALERT', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2004_07_openssl.html', 'name': 'SuSE-SA:2004:007', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.openssl.org/news/secadv_20040317.txt', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc', 'name': 'FreeBSD-SA-04:05', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD', 'x_transferred']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc', 'name': 'NetBSD-SA2004-005', 'tags': ['vendor-advisory', 'x_refsource_NETBSD', 'x_transferred']}, {'url': 'http://www.ciac.org/ciac/bulletins/o-101.shtml', 'name': 'O-101', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA04-078A.html', 'name': 'TA04-078A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17401', 'name': '17401', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-829.html', 'name': 'RHSA-2005:829', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870', 'name': 'oval:org.mitre.oval:def:870', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-830.html', 'name': 'RHSA-2005:830', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://security.gentoo.org/glsa/glsa-200403-03.xml', 'name': 'GLSA-200403-03', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'http://secunia.com/advisories/11139', 'name': '11139', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-120.html', 'name': 'RHSA-2004:120', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=107953412903636&w=2', 'name': '20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html', 'name': 'APPLE-SA-2005-08-15', 'tags': ['vendor-advisory', 'x_refsource_APPLE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17398', 'name': '17398', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961', 'name': 'SSA:2004-077', 'tags': ['vendor-advisory', 'x_refsource_SLACKWARE', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-139.html', 'name': 'RHSA-2004:139', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15505', 'name': 'openssl-dochangecipherspec-dos(15505)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.trustix.org/errata/2004/0012', 'name': '2004-0012', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX', 'x_transferred']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml', 'name': '20040317 Cisco OpenSSL Implementation Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://docs.info.apple.com/article.html?artnum=61798', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/288574', 'name': 'VU#288574', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.debian.org/security/2004/dsa-465', 'name': 'DSA-465', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html', 'name': 'APPLE-SA-2005-08-17', 'tags': ['vendor-advisory', 'x_refsource_APPLE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18247', 'name': '18247', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770', 'name': 'oval:org.mitre.oval:def:5770', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:23.689Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0079', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-08T16:21:54.985893Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-476', 'description': 'CWE-476 NULL Pointer Dereference'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:31:06.392Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-03-17T05:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/9899', 'name': '9899', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html', 'name': 'FEDORA-2005-1042', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html', 'name': 'ESA-20040317-003', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE']}, {'url': 'http://marc.info/?l=bugtraq&m=108403806509920&w=2', 'name': 'SSRT4717', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-121.html', 'name': 'RHSA-2004:121', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2004:023', 'name': 'MDKSA-2004:023', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621', 'name': 'oval:org.mitre.oval:def:2621', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834', 'name': 'CLA-2004:834', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt', 'name': 'SCOSA-2004.10', 'tags': ['vendor-advisory', 'x_refsource_SCO']}, {'url': 'http://secunia.com/advisories/17381', 'name': '17381', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'tags': ['x_refsource_MISC']}, {'url': 'http://fedoranews.org/updates/FEDORA-2004-095.shtml', 'name': 'FEDORA-2004-095', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779', 'name': 'oval:org.mitre.oval:def:9779', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975', 'name': 'oval:org.mitre.oval:def:975', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524', 'name': '57524', 'tags': ['vendor-advisory', 'x_refsource_SUNALERT']}, {'url': 'http://www.novell.com/linux/security/advisories/2004_07_openssl.html', 'name': 'SuSE-SA:2004:007', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.openssl.org/news/secadv_20040317.txt', 'tags': ['x_refsource_CONFIRM']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc', 'name': 'FreeBSD-SA-04:05', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc', 'name': 'NetBSD-SA2004-005', 'tags': ['vendor-advisory', 'x_refsource_NETBSD']}, {'url': 'http://www.ciac.org/ciac/bulletins/o-101.shtml', 'name': 'O-101', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA04-078A.html', 'name': 'TA04-078A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://secunia.com/advisories/17401', 'name': '17401', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-829.html', 'name': 'RHSA-2005:829', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870', 'name': 'oval:org.mitre.oval:def:870', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-830.html', 'name': 'RHSA-2005:830', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://security.gentoo.org/glsa/glsa-200403-03.xml', 'name': 'GLSA-200403-03', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'http://secunia.com/advisories/11139', 'name': '11139', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-120.html', 'name': 'RHSA-2004:120', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://marc.info/?l=bugtraq&m=107953412903636&w=2', 'name': '20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html', 'name': 'APPLE-SA-2005-08-15', 'tags': ['vendor-advisory', 'x_refsource_APPLE']}, {'url': 'http://secunia.com/advisories/17398', 'name': '17398', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961', 'name': 'SSA:2004-077', 'tags': ['vendor-advisory', 'x_refsource_SLACKWARE']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-139.html', 'name': 'RHSA-2004:139', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15505', 'name': 'openssl-dochangecipherspec-dos(15505)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.trustix.org/errata/2004/0012', 'name': '2004-0012', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml', 'name': '20040317 Cisco OpenSSL Implementation Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://docs.info.apple.com/article.html?artnum=61798', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.kb.cert.org/vuls/id/288574', 'name': 'VU#288574', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.debian.org/security/2004/dsa-465', 'name': 'DSA-465', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html', 'name': 'APPLE-SA-2005-08-17', 'tags': ['vendor-advisory', 'x_refsource_APPLE']}, {'url': 'http://secunia.com/advisories/18247', 'name': '18247', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770', 'name': 'oval:org.mitre.oval:def:5770', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}], 'descriptions': [{'lang': 'en', 'value': 'The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-10-10T04:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/9899', 'name': '9899', 'refsource': 'BID'}, {'url': 'http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html', 'name': 'FEDORA-2005-1042', 'refsource': 'FEDORA'}, {'url': 'http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html', 'name': 'ESA-20040317-003', 'refsource': 'ENGARDE'}, {'url': 'http://marc.info/?l=bugtraq&m=108403806509920&w=2', 'name': 'SSRT4717', 'refsource': 'HP'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-121.html', 'name': 'RHSA-2004:121', 'refsource': 'REDHAT'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2004:023', 'name': 'MDKSA-2004:023', 'refsource': 'MANDRAKE'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621', 'name': 'oval:org.mitre.oval:def:2621', 'refsource': 'OVAL'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834', 'name': 'CLA-2004:834', 'refsource': 'CONECTIVA'}, {'url': 'ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt', 'name': 'SCOSA-2004.10', 'refsource': 'SCO'}, {'url': 'http://secunia.com/advisories/17381', 'name': '17381', 'refsource': 'SECUNIA'}, {'url': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'name': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'refsource': 'MISC'}, {'url': 'http://fedoranews.org/updates/FEDORA-2004-095.shtml', 'name': 'FEDORA-2004-095', 'refsource': 'FEDORA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779', 'name': 'oval:org.mitre.oval:def:9779', 'refsource': 'OVAL'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975', 'name': 'oval:org.mitre.oval:def:975', 'refsource': 'OVAL'}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524', 'name': '57524', 'refsource': 'SUNALERT'}, {'url': 'http://www.novell.com/linux/security/advisories/2004_07_openssl.html', 'name': 'SuSE-SA:2004:007', 'refsource': 'SUSE'}, {'url': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'name': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'refsource': 'CONFIRM'}, {'url': 'http://www.openssl.org/news/secadv_20040317.txt', 'name': 'http://www.openssl.org/news/secadv_20040317.txt', 'refsource': 'CONFIRM'}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc', 'name': 'FreeBSD-SA-04:05', 'refsource': 'FREEBSD'}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc', 'name': 'NetBSD-SA2004-005', 'refsource': 'NETBSD'}, {'url': 'http://www.ciac.org/ciac/bulletins/o-101.shtml', 'name': 'O-101', 'refsource': 'CIAC'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA04-078A.html', 'name': 'TA04-078A', 'refsource': 'CERT'}, {'url': 'http://secunia.com/advisories/17401', 'name': '17401', 'refsource': 'SECUNIA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-829.html', 'name': 'RHSA-2005:829', 'refsource': 'REDHAT'}, {'url': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'name': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'refsource': 'CONFIRM'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870', 'name': 'oval:org.mitre.oval:def:870', 'refsource': 'OVAL'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-830.html', 'name': 'RHSA-2005:830', 'refsource': 'REDHAT'}, {'url': 'http://security.gentoo.org/glsa/glsa-200403-03.xml', 'name': 'GLSA-200403-03', 'refsource': 'GENTOO'}, {'url': 'http://secunia.com/advisories/11139', 'name': '11139', 'refsource': 'SECUNIA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-120.html', 'name': 'RHSA-2004:120', 'refsource': 'REDHAT'}, {'url': 'http://marc.info/?l=bugtraq&m=107953412903636&w=2', 'name': '20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]', 'refsource': 'BUGTRAQ'}, {'url': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'name': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'refsource': 'CONFIRM'}, {'url': 'http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html', 'name': 'APPLE-SA-2005-08-15', 'refsource': 'APPLE'}, {'url': 'http://secunia.com/advisories/17398', 'name': '17398', 'refsource': 'SECUNIA'}, {'url': 'http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961', 'name': 'SSA:2004-077', 'refsource': 'SLACKWARE'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-139.html', 'name': 'RHSA-2004:139', 'refsource': 'REDHAT'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15505', 'name': 'openssl-dochangecipherspec-dos(15505)', 'refsource': 'XF'}, {'url': 'http://www.trustix.org/errata/2004/0012', 'name': '2004-0012', 'refsource': 'TRUSTIX'}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml', 'name': '20040317 Cisco OpenSSL Implementation Vulnerability', 'refsource': 'CISCO'}, {'url': 'http://docs.info.apple.com/article.html?artnum=61798', 'name': 'http://docs.info.apple.com/article.html?artnum=61798', 'refsource': 'CONFIRM'}, {'url': 'http://www.kb.cert.org/vuls/id/288574', 'name': 'VU#288574', 'refsource': 'CERT-VN'}, {'url': 'http://www.debian.org/security/2004/dsa-465', 'name': 'DSA-465', 'refsource': 'DEBIAN'}, {'url': 'http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html', 'name': 'APPLE-SA-2005-08-17', 'refsource': 'APPLE'}, {'url': 'http://secunia.com/advisories/18247', 'name': '18247', 'refsource': 'SECUNIA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770', 'name': 'oval:org.mitre.oval:def:5770', 'refsource': 'OVAL'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0079', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0079', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:33:22.869Z', 'dateReserved': '2004-01-19T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-03-18T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-3106 | 4.70 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H | none | no | partial | 2.0.3 | 2024-02-16 19:17:54.787409+03:00 | ['CWE-667'] | 2025-01-16 22:44:22.117000+03:00 | 0fd02f8954416e4bedba0c70d2378b43d02206226c12a7dec70b1ef59e608a49 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9108', 'name': 'oval:org.mitre.oval:def:9108', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0101.html', 'name': 'RHSA-2006:0101', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c%401.156?nav=index.html%7Csrc/%7Csrc/fs%7Chist/fs/exec.c', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/15049', 'name': '15049', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18510', 'name': '18510', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17141', 'name': '17141', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-199-1', 'name': 'USN-199-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2006:072', 'name': 'MDKSA-2006:072', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:01:57.774Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3106', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-16T16:17:54.787409Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-667', 'description': 'CWE-667 Improper Locking'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:44:22.117Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-09-29T00:00:00.000Z', 'references': [{'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9108', 'name': 'oval:org.mitre.oval:def:9108', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0101.html', 'name': 'RHSA-2006:0101', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c%401.156?nav=index.html%7Csrc/%7Csrc/fs%7Chist/fs/exec.c', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.securityfocus.com/bid/15049', 'name': '15049', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/18510', 'name': '18510', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/17141', 'name': '17141', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.ubuntu.com/usn/usn-199-1', 'name': 'USN-199-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2006:072', 'name': 'MDKSA-2006:072', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}], 'descriptions': [{'lang': 'en', 'value': 'Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9108', 'name': 'oval:org.mitre.oval:def:9108', 'refsource': 'OVAL'}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'refsource': 'SECUNIA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0101.html', 'name': 'RHSA-2006:0101', 'refsource': 'REDHAT'}, {'url': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c@1.156?nav=index.html|src/|src/fs|hist/fs/exec.c', 'name': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c@1.156?nav=index.html|src/|src/fs|hist/fs/exec.c', 'refsource': 'CONFIRM'}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'refsource': 'DEBIAN'}, {'url': 'http://www.securityfocus.com/bid/15049', 'name': '15049', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/18510', 'name': '18510', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/17141', 'name': '17141', 'refsource': 'SECUNIA'}, {'url': 'http://www.ubuntu.com/usn/usn-199-1', 'name': 'USN-199-1', 'refsource': 'UBUNTU'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2006:072', 'name': 'MDKSA-2006:072', 'refsource': 'MANDRIVA'}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'refsource': 'FEDORA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3106', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3106', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:44:38.257Z', 'dateReserved': '2005-09-30T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-09-30T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-1794 | 7.40 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N | none | no | total | 2.0.3 | 2026-05-22 13:32:10.235169+03:00 | 2026-05-22 13:32:00.457000+03:00 | 179581b01d8de88bd0b2010be8adc5f4efc4e08e2f477487fd8de6391830f029 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://secunia.com/advisories/15605/', 'name': '15605', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/13818', 'name': '13818', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441', 'name': 'oval:org.mitre.oval:def:12441', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:06:56.561Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1794', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-22T10:32:10.235169Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-22T10:32:00.457Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-05-28T00:00:00.000Z', 'references': [{'url': 'http://secunia.com/advisories/15605/', 'name': '15605', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/13818', 'name': '13818', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441', 'name': 'oval:org.mitre.oval:def:12441', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}], 'descriptions': [{'lang': 'en', 'value': 'Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-03-27T15:57:02.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://secunia.com/advisories/15605/', 'name': '15605', 'refsource': 'SECUNIA'}, {'url': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'name': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/13818', 'name': '13818', 'refsource': 'BID'}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'name': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'refsource': 'MISC'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441', 'name': 'oval:org.mitre.oval:def:12441', 'refsource': 'OVAL'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1794', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1794', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-22T10:33:57.094Z', 'dateReserved': '2005-06-01T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-01T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | ||
CVE-2006-0149 | 6.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | none | no | partial | 2.0.3 | 2025-04-03 17:52:41.844258+03:00 | ['CWE-80'] | 2025-04-03 17:54:25.932000+03:00 | 4b0aa1157ec76dba7b58fbb1e51d6326db4d4d13f2753873f375de36d160b5f7 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securitytracker.com/id?1015451', 'name': '1015451', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html', 'name': '20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability', 'tags': ['mailing-list', 'x_refsource_FULLDISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:25:34.057Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-0149', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-03T14:52:41.844258Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-80', 'description': 'CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T14:54:25.932Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://securitytracker.com/id?1015451', 'name': '1015451', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html', 'name': '20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability', 'tags': ['mailing-list', 'x_refsource_FULLDISC']}], 'descriptions': [{'lang': 'en', 'value': 'Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-01-09T23:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://securitytracker.com/id?1015451', 'name': '1015451', 'refsource': 'SECTRACK'}, {'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html', 'name': '20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability', 'refsource': 'FULLDISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-0149', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-0149', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T14:56:57.175Z', 'dateReserved': '2006-01-09T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-01-09T23:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-1876 | 4.50 | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L | none | no | total | 2.0.3 | 2024-02-14 18:46:22.530197+03:00 | ['CWE-94'] | 2025-01-16 22:11:19.635000+03:00 | 2224a0f3c096a50ae62bbe7910c0427c89cf34094f208759cc84c6e5d5fa9c35 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/17030', 'name': '17030', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111773528322711&w=2', 'name': '20050602 PHP Execution Vulnerability in CuteNews', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/15594', 'name': '15594', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:06:57.133Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1876', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-14T15:46:22.530197Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:11:19.635Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-06-02T04:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/17030', 'name': '17030', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://marc.info/?l=bugtraq&m=111773528322711&w=2', 'name': '20050602 PHP Execution Vulnerability in CuteNews', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/15594', 'name': '15594', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}], 'descriptions': [{'lang': 'en', 'value': 'Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/17030', 'name': '17030', 'refsource': 'OSVDB'}, {'url': 'http://marc.info/?l=bugtraq&m=111773528322711&w=2', 'name': '20050602 PHP Execution Vulnerability in CuteNews', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/15594', 'name': '15594', 'refsource': 'SECUNIA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1876', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1876', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:13:11.881Z', 'dateReserved': '2005-06-08T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-07T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2005-4206 | 6.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | none | no | partial | 2.0.3 | 2025-01-16 22:48:32.555946+03:00 | ['CWE-601'] | 2025-01-16 22:48:13.868000+03:00 | 1fa4ccf9f0ee869dfe54ee923aaaa1a4fb13fc38091ab71eadd51789b7fe9fca | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23558', 'name': 'academicsuite-frameset-crossdomain-loading(23558)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17991', 'name': '17991', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.osvdb.org/21618', 'name': '21618', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/15814', 'name': '15814', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:38:51.545Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4206', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:48:32.555946Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-601', 'description': "CWE-601 URL Redirection to Untrusted Site ('Open Redirect')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:48:13.868Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-11-16T00:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23558', 'name': 'academicsuite-frameset-crossdomain-loading(23558)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'tags': ['x_refsource_MISC']}, {'url': 'http://secunia.com/advisories/17991', 'name': '17991', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.osvdb.org/21618', 'name': '21618', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/15814', 'name': '15814', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23558', 'name': 'academicsuite-frameset-crossdomain-loading(23558)', 'refsource': 'XF'}, {'url': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'name': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'refsource': 'MISC'}, {'url': 'http://secunia.com/advisories/17991', 'name': '17991', 'refsource': 'SECUNIA'}, {'url': 'http://www.osvdb.org/21618', 'name': '21618', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/15814', 'name': '15814', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4206', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4206', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:48:36.106Z', 'dateReserved': '2005-12-13T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-12-13T11:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-0054 | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | none | yes | partial | 2.0.3 | 2024-02-14 19:15:16.514845+03:00 | ['CWE-824'] | 2025-01-16 22:52:58.803000+03:00 | 0b63d49549fec1e932c806e283ae4961a143081600e55257a2cce16a0306e02e | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/22319', 'name': '22319', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/16209', 'name': '16209', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18378', 'name': '18378', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24073', 'name': 'ipfw-icmp-fragment-dos(24073)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc', 'name': 'FreeBSD-SA-06:04', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1015477', 'name': '1015477', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:18:20.791Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-0054', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-14T16:15:16.514845Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-824', 'description': 'CWE-824 Access of Uninitialized Pointer'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:52:58.803Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-01-11T00:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/22319', 'name': '22319', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/16209', 'name': '16209', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/18378', 'name': '18378', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24073', 'name': 'ipfw-icmp-fragment-dos(24073)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc', 'name': 'FreeBSD-SA-06:04', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD']}, {'url': 'http://securitytracker.com/id?1015477', 'name': '1015477', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}], 'descriptions': [{'lang': 'en', 'value': 'The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '63664ac6-956c-4cba-a5d0-f46076e16109', 'shortName': 'freebsd', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/22319', 'name': '22319', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/16209', 'name': '16209', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/18378', 'name': '18378', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24073', 'name': 'ipfw-icmp-fragment-dos(24073)', 'refsource': 'XF'}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc', 'name': 'FreeBSD-SA-06:04', 'refsource': 'FREEBSD'}, {'url': 'http://securitytracker.com/id?1015477', 'name': '1015477', 'refsource': 'SECTRACK'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-0054', 'STATE': 'PUBLIC', 'ASSIGNER': 'secteam@freebsd.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-0054', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:53:05.979Z', 'dateReserved': '2005-12-30T00:00:00.000Z', 'assignerOrgId': '63664ac6-956c-4cba-a5d0-f46076e16109', 'datePublished': '2006-01-11T21:00:00.000Z', 'assignerShortName': 'freebsd'}, 'dataVersion': '5.1'} | |
CVE-2005-4780 | 3.70 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N | none | no | partial | 2.0.3 | 2024-04-15 22:23:25.002384+03:00 | 2025-01-16 23:03:07.838000+03:00 | b316b9c784849db8c24ac78551c8a1e2d7394b8ceebba9dff2add330693f9b07 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/15952', 'name': '15952', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23668', 'name': 'lighthousecms-search-xss(23668)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.lighthouse-cms.de/en/news/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/21852', 'name': '21852', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:22.480Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4780', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-15T19:23:25.002384Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T20:03:07.838Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-12-18T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/15952', 'name': '15952', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23668', 'name': 'lighthousecms-search-xss(23668)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.lighthouse-cms.de/en/news/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/21852', 'name': '21852', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology. [It] is an application server ... A technology like this cannot be susceptible to client-side cross-site-scripting-attacks on its own, but only applications created based on such a technology. This does not only apply to Lighthouse, but also to Perl, PHP or web applications based on Java Servlet technology." Since the original researcher is known to test demo pages and is sometimes inaccurate, it is likely that this issue will be REJECTED'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/15952', 'name': '15952', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23668', 'name': 'lighthousecms-search-xss(23668)', 'refsource': 'XF'}, {'url': 'http://www.lighthouse-cms.de/en/news/', 'name': 'http://www.lighthouse-cms.de/en/news/', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/21852', 'name': '21852', 'refsource': 'OSVDB'}, {'url': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'name': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology. [It] is an application server ... A technology like this cannot be susceptible to client-side cross-site-scripting-attacks on its own, but only applications created based on such a technology. This does not only apply to Lighthouse, but also to Perl, PHP or web applications based on Java Servlet technology." Since the original researcher is known to test demo pages and is sometimes inaccurate, it is likely that this issue will be REJECTED.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4780', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4780', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T20:03:59.554Z', 'dateReserved': '2006-04-13T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-04-14T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2005-4900 | 5.90 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | none | no | partial | 2.0.3 | 2026-05-22 19:17:39.588677+03:00 | ['CWE-327'] | 2026-05-22 19:16:34.456000+03:00 | a0a31fa5aa6097d0d2787dd0d60dbe93db144e7bcf9d7f6919bcfefb125de76f | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://sites.google.com/site/itstheshappening', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/12577', 'name': '12577', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://shattered.io/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://ia.cr/2007/474', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:23.514Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4900', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-22T16:17:39.588677Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-327', 'description': 'CWE-327 Use of a Broken or Risky Cryptographic Algorithm'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-22T16:16:34.456Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-02-15T00:00:00.000Z', 'references': [{'url': 'https://sites.google.com/site/itstheshappening', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/12577', 'name': '12577', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://shattered.io/', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'tags': ['x_refsource_MISC']}, {'url': 'http://ia.cr/2007/474', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'tags': ['x_refsource_MISC']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2020-12-09T08:06:17.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://sites.google.com/site/itstheshappening', 'name': 'https://sites.google.com/site/itstheshappening', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/12577', 'name': '12577', 'refsource': 'BID'}, {'url': 'http://shattered.io/', 'name': 'http://shattered.io/', 'refsource': 'MISC'}, {'url': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'name': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'refsource': 'MISC'}, {'url': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'name': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'refsource': 'MISC'}, {'url': 'http://ia.cr/2007/474', 'name': 'http://ia.cr/2007/474', 'refsource': 'MISC'}, {'url': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'name': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'refsource': 'MISC'}, {'url': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'name': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'refsource': 'MISC'}, {'url': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'name': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'refsource': 'MISC'}, {'url': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'name': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'refsource': 'MISC'}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'name': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4900', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4900', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-22T16:18:17.909Z', 'dateReserved': '2016-10-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2016-10-14T16:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} | |
CVE-2005-4349 | 6.30 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L | none | no | partial | 2.0.3 | 2024-04-15 22:20:51.357317+03:00 | ['CWE-89'] | 2025-01-16 22:49:31.197000+03:00 | 6228279a8237507d010143e870612b33df26e11549d5c0f67123db28431e4dbf | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securityreason.com/securityalert/270', 'name': '270', 'tags': ['third-party-advisory', 'x_refsource_SREASON', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2005/2995', 'name': 'ADV-2005-2995', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=113486637512821&w=2', 'name': '20051217 phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/419829/100/0/threaded', 'name': '20051219 Re: phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18113', 'name': '18113', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/419832/100/0/threaded', 'name': "20051219 about phpMyAdmin's server_privileges.php announced vulnerability", 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:38:51.895Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4349', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-15T19:20:51.357317Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-89', 'description': "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:49:31.197Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-12-17T05:00:00.000Z', 'references': [{'url': 'http://securityreason.com/securityalert/270', 'name': '270', 'tags': ['third-party-advisory', 'x_refsource_SREASON']}, {'url': 'http://www.vupen.com/english/advisories/2005/2995', 'name': 'ADV-2005-2995', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://marc.info/?l=bugtraq&m=113486637512821&w=2', 'name': '20051217 phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/419829/100/0/threaded', 'name': '20051219 Re: phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/18113', 'name': '18113', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securityfocus.com/archive/1/419832/100/0/threaded', 'name': "20051219 about phpMyAdmin's server_privileges.php announced vulnerability", 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://securityreason.com/securityalert/270', 'name': '270', 'refsource': 'SREASON'}, {'url': 'http://www.vupen.com/english/advisories/2005/2995', 'name': 'ADV-2005-2995', 'refsource': 'VUPEN'}, {'url': 'http://marc.info/?l=bugtraq&m=113486637512821&w=2', 'name': '20051217 phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/419829/100/0/threaded', 'name': '20051219 Re: phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/18113', 'name': '18113', 'refsource': 'SECUNIA'}, {'url': 'http://www.securityfocus.com/archive/1/419832/100/0/threaded', 'name': "20051219 about phpMyAdmin's server_privileges.php announced vulnerability", 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4349', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4349', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:49:37.380Z', 'dateReserved': '2005-12-19T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-12-19T16:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-10002 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2026-03-19 20:11:03.634936+03:00 | 2026-03-19 20:11:22.535000+03:00 | 254f252a223137f393ba3373b9c44af6f1ba24b771af4fa10825d3662b7d2046 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2026/03/19/1'}, {'url': 'http://www.openwall.com/lists/oss-security/2026/03/22/3'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2026-03-22T23:06:42.361Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-10002', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-03-19T17:11:03.634936Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-03-19T17:11:22.535Z'}}], 'cna': {'title': 'XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes', 'source': {'discovery': 'UNKNOWN'}, 'affected': [{'repo': 'http://github.com/toddr/XML-Parser', 'vendor': 'TODDR', 'product': 'XML::Parser', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '2.45'}], 'packageName': 'XML-Parser', 'programFiles': ['Expat.xs'], 'collectionURL': 'https://cpan.org/modules', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': 'parse_stream'}]}], 'timeline': [{'lang': 'en', 'time': '2006-06-13T00:00:00.000Z', 'value': 'Issue logged in Request Tracker for XML::Parser'}, {'lang': 'en', 'time': '2006-08-11T00:00:00.000Z', 'value': 'Patch provided in Request Tracker for XML::Parser'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Issue migrated to github issue tracker'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Patch provided in github issue tracker'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Included in release 2.46 released to CPAN'}], 'solutions': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13 or upgrade to version 2.46 or later.'}], 'references': [{'url': 'https://rt.cpan.org/Ticket/Display.html?id=19859', 'tags': ['issue-tracking']}, {'url': 'https://github.com/cpan-authors/XML-Parser/issues/64', 'tags': ['issue-tracking']}, {'url': 'https://metacpan.org/release/TODDR/XML-Parser-2.46/changes', 'tags': ['release-notes']}, {'url': 'https://github.com/cpan-authors/XML-Parser/commit/56b0509dfc6b559cd7555ea81ee62e3622069255.patch', 'tags': ['patch']}], 'workarounds': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13.'}], 'x_generator': {'engine': 'cpansec-cna-tool 0.1'}, 'descriptions': [{'lang': 'en', 'value': "XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes.\n\nA :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while SvPV() gives back multi-byte UTF-8 bytes that can exceed the pre-allocated buffer size. This can cause heap corruption (double free or corruption) and crashes."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-122', 'description': 'CWE-122 Heap-based Buffer Overflow'}]}, {'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-176', 'description': 'CWE-176 Improper Handling of Unicode Encoding'}]}], 'providerMetadata': {'orgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'shortName': 'CPANSec', 'dateUpdated': '2026-03-21T11:43:43.607Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-10002', 'state': 'PUBLISHED', 'dateUpdated': '2026-04-29T14:36:41.837Z', 'dateReserved': '2026-03-16T22:47:45.685Z', 'assignerOrgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'datePublished': '2026-03-19T11:03:46.888Z', 'assignerShortName': 'CPANSec'}, 'dataVersion': '5.2'} | ||
CVE-2006-10003 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2026-03-19 20:08:41.621885+03:00 | 2026-03-19 20:09:53.422000+03:00 | 595f1f413218318f120e94f480914925f0e69c640db8ac5afec71b6785da83ca | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2026/03/19/2'}, {'url': 'https://lists.debian.org/debian-lts-announce/2026/04/msg00002.html'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2026-04-04T08:11:42.558Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-10003', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-03-19T17:08:41.621885Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-03-19T17:09:53.422Z'}}], 'cna': {'title': 'XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack', 'source': {'discovery': 'UNKNOWN'}, 'affected': [{'repo': 'http://github.com/toddr/XML-Parser', 'vendor': 'TODDR', 'product': 'XML::Parser', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '2.47'}], 'packageName': 'XML-Parser', 'programFiles': ['Expat.xs'], 'collectionURL': 'https://cpan.org/modules', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': 'startElement'}]}], 'timeline': [{'lang': 'en', 'time': '2006-06-13T00:00:00.000Z', 'value': 'Issue logged and patch provided in Request Tracker for XML::Parser'}, {'lang': 'en', 'time': '2019-09-23T00:00:00.000Z', 'value': 'Issue migrated to github issue tracker'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Patch provided in github issue tracker'}, {'lang': 'en', 'time': '2026-03-16T00:00:00.000Z', 'value': 'PR created and commit merged to git repo'}], 'solutions': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13 or upgrade to version 2.48 or later when it is released.'}], 'references': [{'url': 'https://rt.cpan.org/Ticket/Display.html?id=19860', 'tags': ['issue-tracking']}, {'url': 'https://github.com/cpan-authors/XML-Parser/issues/39', 'tags': ['issue-tracking']}, {'url': 'https://github.com/cpan-authors/XML-Parser/commit/3eb9cc95420fa0c3f76947c4708962546bf27cfd.patch', 'tags': ['patch']}], 'workarounds': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13.'}], 'x_generator': {'engine': 'cpansec-cna-tool 0.1'}, 'descriptions': [{'lang': 'en', 'value': 'XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.\n\nIn the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer.\n\nThe bug can be observed when parsing an XML file with very deep element nesting'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-193', 'description': 'CWE-193 Off-by-one Error'}]}, {'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-122', 'description': 'CWE-122 Heap-based Buffer Overflow'}]}], 'providerMetadata': {'orgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'shortName': 'CPANSec', 'dateUpdated': '2026-03-19T11:08:04.341Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-10003', 'state': 'PUBLISHED', 'dateUpdated': '2026-04-04T08:11:42.558Z', 'dateReserved': '2026-03-16T22:52:39.890Z', 'assignerOrgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'datePublished': '2026-03-19T11:08:04.341Z', 'assignerShortName': 'CPANSec'}, 'dataVersion': '5.2'} | ||
CVE-2006-2827 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2025-01-17 16:56:32.615352+03:00 | 2025-01-17 16:56:14.844000+03:00 | 9fb69b2771f6ec18c48d216f1e305ce25ccffaa93a13f5301d37a8d1444c4328 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25944', 'name': 'xcart-search-sql-injection(25944)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.osvdb.org/25204', 'name': '25204', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:06:26.640Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-2827', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-17T13:56:32.615352Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T13:56:14.844Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-04-20T00:00:00.000Z', 'references': [{'url': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25944', 'name': 'xcart-search-sql-injection(25944)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.osvdb.org/25204', 'name': '25204', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue in a comment on the original researcher\'s blog, saying "the bug does not impose any security threat and remote attackers can\'t add, modify, or delete information in the back-end database by sending specially-crafted SQL statements to the search.php script using various search parameters." As of 20060605, the original blog entry is unavailable, although ISS also reports the same dispute. CVE has not been able to investigate this issue further, although the researcher sometimes makes inaccurate claims'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'name': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'refsource': 'MISC'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25944', 'name': 'xcart-search-sql-injection(25944)', 'refsource': 'XF'}, {'url': 'http://www.osvdb.org/25204', 'name': '25204', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue in a comment on the original researcher\'s blog, saying "the bug does not impose any security threat and remote attackers can\'t add, modify, or delete information in the back-end database by sending specially-crafted SQL statements to the search.php script using various search parameters." As of 20060605, the original blog entry is unavailable, although ISS also reports the same dispute. CVE has not been able to investigate this issue further, although the researcher sometimes makes inaccurate claims.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-2827', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-2827', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T13:56:38.025Z', 'dateReserved': '2006-06-05T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-06-05T17:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2006-1078 | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2025-01-16 23:01:08.855744+03:00 | 2025-01-16 23:00:16.087000+03:00 | f6e039d3aa5b4e8c897b55a85651d463812185cd919957ed2de7cd927ee9ef0a | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html', 'name': '20070102 Apache 1.3.37 htpasswd buffer overflow vulnerability', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/426823/100/0/threaded', 'name': '20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://marc.info/?l=thttpd&m=114154083000296&w=2', 'name': '[thttpd] 20060305 Re: htpasswd.c security issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://seclists.org/bugtraq/2004/Oct/0359.html', 'name': '20041029 Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/16972', 'name': '16972', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=41279', 'tags': ['x_transferred']}, {'url': 'http://marc.info/?l=thttpd&m=114153031201867&w=2', 'name': '[thttpd] 20060305 htpasswd.c security issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25216', 'name': 'thttpd-command-file-bo(25216)', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html', 'name': '20040916 FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory.', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=31975', 'tags': ['x_transferred']}, {'url': 'http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html', 'name': '20041029 Apache 1.3.33 local buffer overflow in apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/31236', 'name': 'apache-htpasswd-strcpy-bo(31236)', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://seclists.org/fulldisclosure/2023/Nov/13', 'name': '20231127 SEC Consult SA-20231122 :: Multiple Vulnerabilities in m-privacy TightGate-Pro', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:56:15.560Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-1078', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-16T20:01:08.855744Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T20:00:16.087Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-03-05T00:00:00.000Z', 'references': [{'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html', 'name': '20070102 Apache 1.3.37 htpasswd buffer overflow vulnerability', 'tags': ['mailing-list']}, {'url': 'http://www.securityfocus.com/archive/1/426823/100/0/threaded', 'name': '20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.', 'tags': ['mailing-list']}, {'url': 'http://marc.info/?l=thttpd&m=114154083000296&w=2', 'name': '[thttpd] 20060305 Re: htpasswd.c security issues', 'tags': ['mailing-list']}, {'url': 'http://seclists.org/bugtraq/2004/Oct/0359.html', 'name': '20041029 Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list']}, {'url': 'http://www.securityfocus.com/bid/16972', 'name': '16972', 'tags': ['vdb-entry']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=41279'}, {'url': 'http://marc.info/?l=thttpd&m=114153031201867&w=2', 'name': '[thttpd] 20060305 htpasswd.c security issues', 'tags': ['mailing-list']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25216', 'name': 'thttpd-command-file-bo(25216)', 'tags': ['vdb-entry']}, {'url': 'http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html', 'name': '20040916 FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory.', 'tags': ['mailing-list']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=31975'}, {'url': 'http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html', 'name': '20041029 Apache 1.3.33 local buffer overflow in apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/31236', 'name': 'apache-htpasswd-strcpy-bo(31236)', 'tags': ['vdb-entry']}, {'url': 'http://seclists.org/fulldisclosure/2023/Nov/13', 'name': '20231127 SEC Consult SA-20231122 :: Multiple Vulnerabilities in m-privacy TightGate-Pro', 'tags': ['mailing-list']}, {'url': 'http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html'}], 'descriptions': [{'lang': 'en', 'value': 'Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2023-11-28T17:06:25.293Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-1078', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T20:02:13.764Z', 'dateReserved': '2006-03-08T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-03-09T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2006-2362 | 7.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | partial | 2.0.3 | 2025-01-16 23:05:43.320995+03:00 | ['CWE-787'] | 2025-01-16 23:04:43.491000+03:00 | 35ad6f0dcd716176d06966264a0c6d37444f33eff4c25940165e2d5577070d74 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://secunia.com/advisories/20188', 'name': '20188', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20550', 'name': '20550', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/22932', 'name': '22932', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/27441', 'name': '27441', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.trustix.org/errata/2006/0034/', 'name': '2006-0034', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/17950', 'name': '17950', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.html', 'name': '[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2007/3665', 'name': 'ADV-2007-3665', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2006_26_sr.html', 'name': 'SUSE-SR:2006:026', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/1924', 'name': 'ADV-2006-1924', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.securitytracker.com/id?1018872', 'name': '1018872', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20531', 'name': '20531', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-292-1', 'name': 'USN-292-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html', 'name': 'APPLE-SA-2007-10-30', 'tags': ['vendor-advisory', 'x_refsource_APPLE', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26644', 'name': 'binutils-libbfd-bo(26644)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T17:51:04.067Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-2362', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T20:05:43.320995Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-787', 'description': 'CWE-787 Out-of-bounds Write'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T20:04:43.491Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-04-18T04:00:00.000Z', 'references': [{'url': 'http://secunia.com/advisories/20188', 'name': '20188', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/20550', 'name': '20550', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/22932', 'name': '22932', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/27441', 'name': '27441', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.trustix.org/errata/2006/0034/', 'name': '2006-0034', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX']}, {'url': 'http://www.securityfocus.com/bid/17950', 'name': '17950', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.html', 'name': '[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'http://www.vupen.com/english/advisories/2007/3665', 'name': 'ADV-2007-3665', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.novell.com/linux/security/advisories/2006_26_sr.html', 'name': 'SUSE-SR:2006:026', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.vupen.com/english/advisories/2006/1924', 'name': 'ADV-2006-1924', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.securitytracker.com/id?1018872', 'name': '1018872', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://secunia.com/advisories/20531', 'name': '20531', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.ubuntu.com/usn/usn-292-1', 'name': 'USN-292-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html', 'name': 'APPLE-SA-2007-10-30', 'tags': ['vendor-advisory', 'x_refsource_APPLE']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26644', 'name': 'binutils-libbfd-bo(26644)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T19:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://secunia.com/advisories/20188', 'name': '20188', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/20550', 'name': '20550', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/22932', 'name': '22932', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/27441', 'name': '27441', 'refsource': 'SECUNIA'}, {'url': 'http://www.trustix.org/errata/2006/0034/', 'name': '2006-0034', 'refsource': 'TRUSTIX'}, {'url': 'http://www.securityfocus.com/bid/17950', 'name': '17950', 'refsource': 'BID'}, {'url': 'http://www.mail-archive.com/bug-binutils@gnu.org/msg01516.html', 'name': '[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.', 'refsource': 'MLIST'}, {'url': 'http://www.vupen.com/english/advisories/2007/3665', 'name': 'ADV-2007-3665', 'refsource': 'VUPEN'}, {'url': 'http://www.novell.com/linux/security/advisories/2006_26_sr.html', 'name': 'SUSE-SR:2006:026', 'refsource': 'SUSE'}, {'url': 'http://www.vupen.com/english/advisories/2006/1924', 'name': 'ADV-2006-1924', 'refsource': 'VUPEN'}, {'url': 'http://www.securitytracker.com/id?1018872', 'name': '1018872', 'refsource': 'SECTRACK'}, {'url': 'http://secunia.com/advisories/20531', 'name': '20531', 'refsource': 'SECUNIA'}, {'url': 'http://www.ubuntu.com/usn/usn-292-1', 'name': 'USN-292-1', 'refsource': 'UBUNTU'}, {'url': 'http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html', 'name': 'APPLE-SA-2007-10-30', 'refsource': 'APPLE'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26644', 'name': 'binutils-libbfd-bo(26644)', 'refsource': 'XF'}, {'url': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'name': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-2362', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-2362', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T20:05:47.171Z', 'dateReserved': '2006-05-15T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-05-15T20:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-2492 | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | active | no | total | 2.0.3 | 2025-02-07 16:11:21.653549+03:00 | ['CWE-120'] | 2025-02-07 16:11:28.960000+03:00 | 4296a0baf3f3c1196f26ccdb5b1523e4f47fef14c7777ce0e0dc1b2e698fd219 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027', 'name': 'MS06-027', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068', 'name': 'oval:org.mitre.oval:def:2068', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://isc.sans.org/diary.php?storyid=1345', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/25635', 'name': '25635', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738', 'name': 'oval:org.mitre.oval:def:1738', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://isc.sans.org/diary.php?storyid=1346', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-164A.html', 'name': 'TA06-164A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/1872', 'name': 'ADV-2006-1872', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/18037', 'name': '18037', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20153', 'name': '20153', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26556', 'name': 'word-code-execution(26556)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/446012', 'name': 'VU#446012', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1016130', 'name': '1016130', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418', 'name': 'oval:org.mitre.oval:def:1418', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-139A.html', 'name': 'TA06-139A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T17:51:04.545Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-2492', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T13:11:21.653549Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-06-08', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-2492'}}}], 'timeline': [{'lang': 'en', 'time': '2022-06-08T00:00:00.000Z', 'value': 'CVE-2006-2492 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-2492', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-120', 'description': "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T13:11:28.960Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-05-19T00:00:00.000Z', 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027', 'name': 'MS06-027', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068', 'name': 'oval:org.mitre.oval:def:2068', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://isc.sans.org/diary.php?storyid=1345', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/25635', 'name': '25635', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738', 'name': 'oval:org.mitre.oval:def:1738', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://isc.sans.org/diary.php?storyid=1346', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-164A.html', 'name': 'TA06-164A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.vupen.com/english/advisories/2006/1872', 'name': 'ADV-2006-1872', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.securityfocus.com/bid/18037', 'name': '18037', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/20153', 'name': '20153', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26556', 'name': 'word-code-execution(26556)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.kb.cert.org/vuls/id/446012', 'name': 'VU#446012', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://securitytracker.com/id?1016130', 'name': '1016130', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418', 'name': 'oval:org.mitre.oval:def:1418', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-139A.html', 'name': 'TA06-139A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '37e5125f-f79b-445b-8fad-9564f167944b', 'shortName': 'certcc', 'dateUpdated': '2018-10-12T19:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027', 'name': 'MS06-027', 'refsource': 'MS'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068', 'name': 'oval:org.mitre.oval:def:2068', 'refsource': 'OVAL'}, {'url': 'http://isc.sans.org/diary.php?storyid=1345', 'name': 'http://isc.sans.org/diary.php?storyid=1345', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/25635', 'name': '25635', 'refsource': 'OSVDB'}, {'url': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'name': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'refsource': 'CONFIRM'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738', 'name': 'oval:org.mitre.oval:def:1738', 'refsource': 'OVAL'}, {'url': 'http://isc.sans.org/diary.php?storyid=1346', 'name': 'http://isc.sans.org/diary.php?storyid=1346', 'refsource': 'MISC'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-164A.html', 'name': 'TA06-164A', 'refsource': 'CERT'}, {'url': 'http://www.vupen.com/english/advisories/2006/1872', 'name': 'ADV-2006-1872', 'refsource': 'VUPEN'}, {'url': 'http://www.securityfocus.com/bid/18037', 'name': '18037', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/20153', 'name': '20153', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26556', 'name': 'word-code-execution(26556)', 'refsource': 'XF'}, {'url': 'http://www.kb.cert.org/vuls/id/446012', 'name': 'VU#446012', 'refsource': 'CERT-VN'}, {'url': 'http://securitytracker.com/id?1016130', 'name': '1016130', 'refsource': 'SECTRACK'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418', 'name': 'oval:org.mitre.oval:def:1418', 'refsource': 'OVAL'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-139A.html', 'name': 'TA06-139A', 'refsource': 'CERT'}, {'url': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'name': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-2492', 'STATE': 'PUBLIC', 'ASSIGNER': 'cert@cert.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-2492', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:56.729Z', 'dateReserved': '2006-05-19T00:00:00.000Z', 'assignerOrgId': '37e5125f-f79b-445b-8fad-9564f167944b', 'datePublished': '2006-05-20T00:00:00.000Z', 'assignerShortName': 'certcc'}, 'dataVersion': '5.1'} | |
CVE-2006-20001 | none | no | partial | 2.0.3 | 2024-08-01 18:32:06.669346+03:00 | 2024-08-01 18:32:24.196000+03:00 | 08183700adc30198ac37f78e6a5bf61878e7fcd5b781210eacd4e849ed183e19 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://security.netapp.com/advisory/ntap-20230316-0005/'}, {'url': 'https://httpd.apache.org/security/vulnerabilities_24.html', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202309-01', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T20:57:41.059Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-20001', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T15:32:06.669346Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T15:32:24.196Z'}}], 'cna': {'title': 'Apache HTTP Server: mod_dav out of bounds read, or write of zero byte', 'source': {'discovery': 'UNKNOWN'}, 'metrics': [{'other': {'type': 'Textual description of severity', 'content': {'text': 'moderate'}}}], 'affected': [{'vendor': 'Apache Software Foundation', 'product': 'Apache HTTP Server', 'versions': [{'status': 'affected', 'version': '2.4', 'versionType': 'semver', 'lessThanOrEqual': '2.4.54'}], 'defaultStatus': 'unaffected'}], 'timeline': [{'lang': 'en', 'time': '2006-10-31T09:00:00.000Z', 'value': 'Described in first edition of "The Art of Software Security Assessment"'}, {'lang': 'en', 'time': '2022-08-10T12:00:00.000Z', 'value': 'Reported to security team'}], 'references': [{'url': 'https://httpd.apache.org/security/vulnerabilities_24.html', 'tags': ['vendor-advisory']}, {'url': 'https://security.gentoo.org/glsa/202309-01'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.\n\nThis issue affects Apache HTTP Server 2.4.54 and earlier.', 'supportingMedia': [{'type': 'text/html', 'value': 'A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.<br><br>This issue affects Apache HTTP Server 2.4.54 and earlier.<br>', 'base64': False}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-787', 'description': 'CWE-787 Out-of-bounds Write'}]}], 'providerMetadata': {'orgId': 'f0158376-9dc2-43b6-827c-5f631a4d8d09', 'shortName': 'apache', 'dateUpdated': '2023-09-08T21:06:27.122Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-20001', 'state': 'PUBLISHED', 'dateUpdated': '2025-02-13T16:27:07.996Z', 'dateReserved': '2022-09-01T14:24:05.065Z', 'assignerOrgId': 'f0158376-9dc2-43b6-827c-5f631a4d8d09', 'datePublished': '2023-01-17T19:07:27.136Z', 'assignerShortName': 'apache'}, 'dataVersion': '5.1'} | ||||
CVE-2006-1547 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | active | yes | partial | 2.0.3 | 2025-02-07 16:35:54.338056+03:00 | ['CWE-749'] | 2025-02-07 16:26:17.027000+03:00 | bc09e5a272e64cb6d858197a00bf03e332753584eaa47421f6e3ac8045ba250a | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securitytracker.com/id?1015856', 'name': '1015856', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/1205', 'name': 'ADV-2006-1205', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/17342', 'name': '17342', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/19493', 'name': '19493', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25613', 'name': 'struts-actionform-dos(25613)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html', 'name': 'SUSE-SR:2006:010', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20117', 'name': '20117', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=38534', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T17:19:48.247Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-1547', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-02-07T13:35:54.338056Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-01-21', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-1547'}}}], 'timeline': [{'lang': 'en', 'time': '2022-01-21T00:00:00.000Z', 'value': 'CVE-2006-1547 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-1547', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-749', 'description': 'CWE-749 Exposed Dangerous Method or Function'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T13:26:17.027Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-03-30T00:00:00.000Z', 'references': [{'url': 'http://securitytracker.com/id?1015856', 'name': '1015856', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.vupen.com/english/advisories/2006/1205', 'name': 'ADV-2006-1205', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.securityfocus.com/bid/17342', 'name': '17342', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/19493', 'name': '19493', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25613', 'name': 'struts-actionform-dos(25613)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html', 'name': 'SUSE-SR:2006:010', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://secunia.com/advisories/20117', 'name': '20117', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=38534', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2017-07-19T15:57:01.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-1547', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:56.875Z', 'dateReserved': '2006-03-30T00:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2006-03-30T22:00:00.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'} | |
CVE-2006-3547 | 5.50 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | none | no | partial | 2.0.3 | 2024-04-15 21:27:47.510692+03:00 | 2025-01-17 16:58:34.915000+03:00 | 062886d21054b6f81a48d08fb911cf05bbeee65e3a558d9b6f5065e455365107 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/437806/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437809/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/27524', 'name': '27524', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437756/100/200/threaded', 'name': '20060618 Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:30:34.372Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-3547', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-15T18:27:47.510692Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T13:58:34.915Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-06-18T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/437806/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/437809/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/27524', 'name': '27524', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/437756/100/200/threaded', 'name': '20060618 Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-18T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/437806/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/437809/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/27524', 'name': '27524', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/437756/100/200/threaded', 'name': '20060618 Vm ware 0day dos exploit by n00b.', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-3547', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-3547', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T13:58:42.936Z', 'dateReserved': '2006-07-12T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-07-13T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2006-3136 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2024-04-15 21:14:06.571615+03:00 | ['CWE-94'] | 2025-01-17 16:57:28.939000+03:00 | e3d6c3d7c1535156657bb66bed9ed66b8b74bcad4cd5cbddf91c6781f3b594eb | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/27502', 'name': '27502', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437986/100/200/threaded', 'name': '20060617 Re: file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://securityreason.com/securityalert/1120', 'name': '1120', 'tags': ['third-party-advisory', 'x_refsource_SREASON', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/2408', 'name': 'ADV-2006-2408', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1016325', 'name': '1016325', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437423/100/0/threaded', 'name': '20060616 file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/18475', 'name': '18475', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:16:05.875Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-3136', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-04-15T18:14:06.571615Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T13:57:28.939Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-06-16T04:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/27502', 'name': '27502', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/437986/100/200/threaded', 'name': '20060617 Re: file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://securityreason.com/securityalert/1120', 'name': '1120', 'tags': ['third-party-advisory', 'x_refsource_SREASON']}, {'url': 'http://www.vupen.com/english/advisories/2006/2408', 'name': 'ADV-2006-2408', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://securitytracker.com/id?1016325', 'name': '1016325', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.securityfocus.com/archive/1/437423/100/0/threaded', 'name': '20060616 file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/18475', 'name': '18475', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-18T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/27502', 'name': '27502', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/437986/100/200/threaded', 'name': '20060617 Re: file include exploits in nucleus 3.23', 'refsource': 'BUGTRAQ'}, {'url': 'http://securityreason.com/securityalert/1120', 'name': '1120', 'refsource': 'SREASON'}, {'url': 'http://www.vupen.com/english/advisories/2006/2408', 'name': 'ADV-2006-2408', 'refsource': 'VUPEN'}, {'url': 'http://securitytracker.com/id?1016325', 'name': '1016325', 'refsource': 'SECTRACK'}, {'url': 'http://www.securityfocus.com/archive/1/437423/100/0/threaded', 'name': '20060616 file include exploits in nucleus 3.23', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/18475', 'name': '18475', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-3136', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-3136', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T13:57:51.051Z', 'dateReserved': '2006-06-22T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-06-23T02:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-0755 | 5.60 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L | none | yes | total | 2.0.3 | 2024-04-15 21:06:59.724935+03:00 | 2025-01-16 22:57:32.174000+03:00 | 7ffc8c1a7e4340d4c7a612fa23f3732b33ff5efe388685de41c6d03135ab129c | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/424957/100/0/threaded', 'name': '20060214 dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/23210', 'name': '23210', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23216', 'name': '23216', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23217', 'name': '23217', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18879', 'name': '18879', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.osvdb.org/23209', 'name': '23209', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/16648', 'name': '16648', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.osvdb.org/23212', 'name': '23212', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23215', 'name': '23215', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24738', 'name': 'dotproject-multiple-basedir-file-include(24738)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.osvdb.org/23213', 'name': '23213', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/0604', 'name': 'ADV-2006-0604', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.osvdb.org/23214', 'name': '23214', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23218', 'name': '23218', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23211', 'name': '23211', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23219', 'name': '23219', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/425285/100/0/threaded', 'name': '20060215 Re: dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:48:56.618Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.6, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-0755', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-04-15T18:06:59.724935Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:57:32.174Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-02-14T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/424957/100/0/threaded', 'name': '20060214 dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/23210', 'name': '23210', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23216', 'name': '23216', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23217', 'name': '23217', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://secunia.com/advisories/18879', 'name': '18879', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.osvdb.org/23209', 'name': '23209', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/16648', 'name': '16648', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.osvdb.org/23212', 'name': '23212', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23215', 'name': '23215', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24738', 'name': 'dotproject-multiple-basedir-file-include(24738)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.osvdb.org/23213', 'name': '23213', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.vupen.com/english/advisories/2006/0604', 'name': 'ADV-2006-0604', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.osvdb.org/23214', 'name': '23214', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23218', 'name': '23218', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23211', 'name': '23211', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23219', 'name': '23219', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/425285/100/0/threaded', 'name': '20060215 Re: dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/424957/100/0/threaded', 'name': '20060214 dotproject <= 2.0.1 remote code execution', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/23210', 'name': '23210', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23216', 'name': '23216', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23217', 'name': '23217', 'refsource': 'OSVDB'}, {'url': 'http://secunia.com/advisories/18879', 'name': '18879', 'refsource': 'SECUNIA'}, {'url': 'http://www.osvdb.org/23209', 'name': '23209', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/16648', 'name': '16648', 'refsource': 'BID'}, {'url': 'http://www.osvdb.org/23212', 'name': '23212', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23215', 'name': '23215', 'refsource': 'OSVDB'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24738', 'name': 'dotproject-multiple-basedir-file-include(24738)', 'refsource': 'XF'}, {'url': 'http://www.osvdb.org/23213', 'name': '23213', 'refsource': 'OSVDB'}, {'url': 'http://www.vupen.com/english/advisories/2006/0604', 'name': 'ADV-2006-0604', 'refsource': 'VUPEN'}, {'url': 'http://www.osvdb.org/23214', 'name': '23214', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23218', 'name': '23218', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23211', 'name': '23211', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23219', 'name': '23219', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/425285/100/0/threaded', 'name': '20060215 Re: dotproject <= 2.0.1 remote code execution', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-0755', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-0755', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:58:25.845Z', 'dateReserved': '2006-02-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-02-18T02:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | ||
CVE-2006-3730 | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | poc | no | total | 2.0.3 | 2026-02-25 20:54:05.428144+03:00 | ['CWE-94'] | ['https://www.exploit-db.com/exploits/2440'] | 2026-01-12 17:44:32.572000+03:00 | 6ce5e63e25aeb9c48e51d0032467e426b93f95833b75af54160d25841452a657 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securitytracker.com/id?1016941', 'name': '1016941', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-283A.html', 'name': 'TA06-283A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-270A.html', 'name': 'TA06-270A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-057', 'name': 'MS06-057', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/753044', 'name': 'VU#753044', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447174/100/0/threaded', 'name': '20060927 Exploit module available for WebViewFolderIcon setSlice 0-day', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A339', 'name': 'oval:org.mitre.oval:def:339', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://isc.sans.org/diary.php?storyid=1742', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/27804', 'name': 'ie-webviewfoldericon-dos(27804)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447383/100/100/threaded', 'name': '20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447426/100/0/threaded', 'name': '20060930 setSlice exploited in the wild - massively', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://riosec.com/msie-setslice-vuln', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.osvdb.org/27110', 'name': '27110', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/19030', 'name': '19030', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/2882', 'name': 'ADV-2006-2882', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.exploit-db.com/exploits/2440', 'name': '2440', 'tags': ['exploit', 'x_refsource_EXPLOIT-DB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447490/100/0/threaded', 'name': '20060930 ZERT patch for setSlice()', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/22159', 'name': '22159', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:39:54.001Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-3730', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'poc'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-02-25T17:54:05.428144Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-01-12T14:44:32.572Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-07-18T00:00:00.000Z', 'references': [{'url': 'http://securitytracker.com/id?1016941', 'name': '1016941', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-283A.html', 'name': 'TA06-283A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-270A.html', 'name': 'TA06-270A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-057', 'name': 'MS06-057', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.kb.cert.org/vuls/id/753044', 'name': 'VU#753044', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.securityfocus.com/archive/1/447174/100/0/threaded', 'name': '20060927 Exploit module available for WebViewFolderIcon setSlice 0-day', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A339', 'name': 'oval:org.mitre.oval:def:339', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://isc.sans.org/diary.php?storyid=1742', 'tags': ['x_refsource_MISC']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/27804', 'name': 'ie-webviewfoldericon-dos(27804)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/archive/1/447383/100/100/threaded', 'name': '20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/447426/100/0/threaded', 'name': '20060930 setSlice exploited in the wild - massively', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://riosec.com/msie-setslice-vuln', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.osvdb.org/27110', 'name': '27110', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/19030', 'name': '19030', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.vupen.com/english/advisories/2006/2882', 'name': 'ADV-2006-2882', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.exploit-db.com/exploits/2440', 'name': '2440', 'tags': ['exploit', 'x_refsource_EXPLOIT-DB']}, {'url': 'http://www.securityfocus.com/archive/1/447490/100/0/threaded', 'name': '20060930 ZERT patch for setSlice()', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/22159', 'name': '22159', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}], 'descriptions': [{'lang': 'en', 'value': 'Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-17T20:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://securitytracker.com/id?1016941', 'name': '1016941', 'refsource': 'SECTRACK'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-283A.html', 'name': 'TA06-283A', 'refsource': 'CERT'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-270A.html', 'name': 'TA06-270A', 'refsource': 'CERT'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-057', 'name': 'MS06-057', 'refsource': 'MS'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'refsource': 'HP'}, {'url': 'http://www.kb.cert.org/vuls/id/753044', 'name': 'VU#753044', 'refsource': 'CERT-VN'}, {'url': 'http://www.securityfocus.com/archive/1/447174/100/0/threaded', 'name': '20060927 Exploit module available for WebViewFolderIcon setSlice 0-day', 'refsource': 'BUGTRAQ'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A339', 'name': 'oval:org.mitre.oval:def:339', 'refsource': 'OVAL'}, {'url': 'http://isc.sans.org/diary.php?storyid=1742', 'name': 'http://isc.sans.org/diary.php?storyid=1742', 'refsource': 'MISC'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/27804', 'name': 'ie-webviewfoldericon-dos(27804)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/archive/1/447383/100/100/threaded', 'name': '20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/447426/100/0/threaded', 'name': '20060930 setSlice exploited in the wild - massively', 'refsource': 'BUGTRAQ'}, {'url': 'http://riosec.com/msie-setslice-vuln', 'name': 'http://riosec.com/msie-setslice-vuln', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'refsource': 'HP'}, {'url': 'http://www.osvdb.org/27110', 'name': '27110', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/19030', 'name': '19030', 'refsource': 'BID'}, {'url': 'http://www.vupen.com/english/advisories/2006/2882', 'name': 'ADV-2006-2882', 'refsource': 'VUPEN'}, {'url': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'name': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'refsource': 'MISC'}, {'url': 'https://www.exploit-db.com/exploits/2440', 'name': '2440', 'refsource': 'EXPLOIT-DB'}, {'url': 'http://www.securityfocus.com/archive/1/447490/100/0/threaded', 'name': '20060930 ZERT patch for setSlice()', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/22159', 'name': '22159', 'refsource': 'SECUNIA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-3730', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-3730', 'state': 'PUBLISHED', 'dateUpdated': '2026-02-25T17:54:35.799Z', 'dateReserved': '2006-07-19T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-07-19T23:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'} |
CVE-2006-5393 | 5.50 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | none | no | partial | 2.0.3 | 2025-04-03 18:40:54.413762+03:00 | ['CWE-125'] | 2025-04-03 18:41:47.270000+03:00 | 2ba70b128216429a56cf97c109bc9c6717d0ca6c08be188b9b0194d9a2560de0 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml', 'name': '20061009 Limitations in Cisco Secure Desktop', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/20410', 'name': '20410', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1017018', 'name': '1017018', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:48:30.336Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5393', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:40:54.413762Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:41:47.270Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-10-09T00:00:00.000Z', 'references': [{'url': 'http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml', 'name': '20061009 Limitations in Cisco Secure Desktop', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://www.securityfocus.com/bid/20410', 'name': '20410', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://securitytracker.com/id?1017018', 'name': '1017018', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}], 'descriptions': [{'lang': 'en', 'value': "Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-11-08T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml', 'name': '20061009 Limitations in Cisco Secure Desktop', 'refsource': 'CISCO'}, {'url': 'http://www.securityfocus.com/bid/20410', 'name': '20410', 'refsource': 'BID'}, {'url': 'http://securitytracker.com/id?1017018', 'name': '1017018', 'refsource': 'SECTRACK'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5393', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5393', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:41:56.776Z', 'dateReserved': '2006-10-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-10-18T19:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-5708 | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | none | yes | partial | 2.0.3 | 2025-04-03 18:25:25.541724+03:00 | ['CWE-400'] | 2025-04-03 18:25:07.817000+03:00 | 10febbc3d7072ab544addf6decc9792c7a22d6dc7ac17f99bb6d4ee844608cb2 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T20:04:54.460Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5708', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:25:25.541724Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:25:07.817Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-11-04T01:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'name': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5708', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5708', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:26:14.870Z', 'dateReserved': '2006-11-03T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-11-04T01:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-4692 | none | no | partial | 2.0.3 | 2024-10-15 17:15:25.340433+03:00 | 2024-10-15 17:16:27.152000+03:00 | 797b2c741e51964c3a508b4cea683ecb69007907f2ec819fc75c129b70e15d76 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/29424', 'name': '29424', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/703936', 'name': 'VU#703936', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/20318', 'name': '20318', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-065', 'name': 'MS06-065', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/3984', 'name': 'ADV-2006-3984', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://secunia.com/secunia_research/2006-54/advisory/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/448696/100/0/threaded', 'name': '20061014 Re: Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20717', 'name': '20717', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496', 'name': 'oval:org.mitre.oval:def:496', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/448273/100/0/threaded', 'name': '20061011 Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1017037', 'name': '1017037', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:23:40.860Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-4692', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-10-15T14:15:25.340433Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-15T14:16:27.152Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-10-10T04:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/29424', 'name': '29424', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.kb.cert.org/vuls/id/703936', 'name': 'VU#703936', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.securityfocus.com/bid/20318', 'name': '20318', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-065', 'name': 'MS06-065', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.vupen.com/english/advisories/2006/3984', 'name': 'ADV-2006-3984', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://secunia.com/secunia_research/2006-54/advisory/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.securityfocus.com/archive/1/448696/100/0/threaded', 'name': '20061014 Re: Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/20717', 'name': '20717', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496', 'name': 'oval:org.mitre.oval:def:496', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/archive/1/448273/100/0/threaded', 'name': '20061011 Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://securitytracker.com/id?1017037', 'name': '1017037', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}], 'descriptions': [{'lang': 'en', 'value': 'Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': 'f38d906d-7342-40ea-92c1-6c4a2c6478c8', 'shortName': 'microsoft', 'dateUpdated': '2018-10-18T00:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/29424', 'name': '29424', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'refsource': 'HP'}, {'url': 'http://www.kb.cert.org/vuls/id/703936', 'name': 'VU#703936', 'refsource': 'CERT-VN'}, {'url': 'http://www.securityfocus.com/bid/20318', 'name': '20318', 'refsource': 'BID'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-065', 'name': 'MS06-065', 'refsource': 'MS'}, {'url': 'http://www.vupen.com/english/advisories/2006/3984', 'name': 'ADV-2006-3984', 'refsource': 'VUPEN'}, {'url': 'http://secunia.com/secunia_research/2006-54/advisory/', 'name': 'http://secunia.com/secunia_research/2006-54/advisory/', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'refsource': 'HP'}, {'url': 'http://www.securityfocus.com/archive/1/448696/100/0/threaded', 'name': '20061014 Re: Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/20717', 'name': '20717', 'refsource': 'SECUNIA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496', 'name': 'oval:org.mitre.oval:def:496', 'refsource': 'OVAL'}, {'url': 'http://www.securityfocus.com/archive/1/448273/100/0/threaded', 'name': '20061011 Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'refsource': 'BUGTRAQ'}, {'url': 'http://securitytracker.com/id?1017037', 'name': '1017037', 'refsource': 'SECTRACK'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-4692', 'STATE': 'PUBLIC', 'ASSIGNER': 'secure@microsoft.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-4692', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-15T14:16:30.576Z', 'dateReserved': '2006-09-11T04:00:00.000Z', 'assignerOrgId': 'f38d906d-7342-40ea-92c1-6c4a2c6478c8', 'datePublished': '2006-10-11T02:00:00.000Z', 'assignerShortName': 'microsoft'}, 'dataVersion': '5.1'} | ||||
CVE-2006-5014 | 8.80 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | none | no | total | 2.0.3 | 2025-04-03 18:19:40.900742+03:00 | ['CWE-276'] | 2025-04-03 18:20:34.813000+03:00 | 012256b959432049cb378a10b753d6f992d18101eca1140b4affc09bca2e7361 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://forums.cpanel.net/showthread.php?t=58134', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1016913', 'name': '1016913', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://secunia.com/advisories/22072', 'name': '22072', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://changelog.cpanel.net/?build=&showall=1', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/20163', 'name': '20163', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:32:22.871Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5014', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:19:40.900742Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-276', 'description': 'CWE-276 Incorrect Default Permissions'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:20:34.813Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://forums.cpanel.net/showthread.php?t=58134', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://securitytracker.com/id?1016913', 'name': '1016913', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://secunia.com/advisories/22072', 'name': '22072', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://changelog.cpanel.net/?build=&showall=1', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/bid/20163', 'name': '20163', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-09-27T01:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://forums.cpanel.net/showthread.php?t=58134', 'name': 'http://forums.cpanel.net/showthread.php?t=58134', 'refsource': 'CONFIRM'}, {'url': 'http://securitytracker.com/id?1016913', 'name': '1016913', 'refsource': 'SECTRACK'}, {'url': 'http://secunia.com/advisories/22072', 'name': '22072', 'refsource': 'SECUNIA'}, {'url': 'http://changelog.cpanel.net/?build=&showall=1', 'name': 'http://changelog.cpanel.net/?build=&showall=1', 'refsource': 'CONFIRM'}, {'url': 'http://www.securityfocus.com/bid/20163', 'name': '20163', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5014', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5014', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:20:50.861Z', 'dateReserved': '2006-09-26T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-09-27T01:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-5021 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2025-04-03 18:17:19.693482+03:00 | ['CWE-94'] | 2025-04-03 18:17:59.385000+03:00 | 89f4d1e7fc84d67f6252a5e5fbc340afd2b62b0dd4b53a1d48812fa649216f82 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/20115', 'name': '20115', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:32:22.960Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5021', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:17:19.693482Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:17:59.385Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/bid/20115', 'name': '20115', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-09-27T23:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/20115', 'name': '20115', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5021', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5021', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:18:24.691Z', 'dateReserved': '2006-09-27T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-09-27T23:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} | |
CVE-2006-4428 | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | none | yes | total | 2.0.3 | 2025-01-17 17:01:37.355489+03:00 | 2025-01-17 17:01:18.199000+03:00 | 66bb8c231a7c76b75d2afca69fd2ef8fd36cddcb54eab6c520ab3a3b10bc9cb9 | 2026-05-29 05:09:33.454344+03:00 | 2026-05-29 05:09:33.454344+03:00 | {'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/444421/100/0/threaded', 'name': '20060825 Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/28298', 'name': '28298', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/444729/100/0/threaded', 'name': '20060829 Re: Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.attrition.org/pipermail/vim/2006-August/000996.html', 'name': '20060828 Jupiter CMS file include - CVE dispute', 'tags': ['mailing-list', 'x_refsource_VIM', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/28589', 'name': 'jupitercm-index-file-include(28589)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/19721', 'name': '19721', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:06:07.753Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-4428', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-17T14:01:37.355489Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T14:01:18.199Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-08-25T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/444421/100/0/threaded', 'name': '20060825 Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/28298', 'name': '28298', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/444729/100/0/threaded', 'name': '20060829 Re: Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.attrition.org/pipermail/vim/2006-August/000996.html', 'name': '20060828 Jupiter CMS file include - CVE dispute', 'tags': ['mailing-list', 'x_refsource_VIM']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/28589', 'name': 'jupitercm-index-file-include(28589)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/bid/19721', 'name': '19721', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-17T20:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/444421/100/0/threaded', 'name': '20060825 Jupiter CMS 1.1.5 index.php Remote File Include', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/28298', 'name': '28298', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/444729/100/0/threaded', 'name': '20060829 Re: Jupiter CMS 1.1.5 index.php Remote File Include', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.attrition.org/pipermail/vim/2006-August/000996.html', 'name': '20060828 Jupiter CMS file include - CVE dispute', 'refsource': 'VIM'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/28589', 'name': 'jupitercm-index-file-include(28589)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/bid/19721', 'name': '19721', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-4428', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-4428', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T14:01:42.279Z', 'dateReserved': '2006-08-28T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-08-29T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'} |