/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/vulnrichment.csv
101 строка566 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-1999-0038
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-09-04 17:24:32.065476+03:00
['CWE-120']
2024-09-04 17:07:08.502000+03:00
ffa82fab84ca9789215fef22dbd2ac33ad2f6f5dbe73ef8c713f827bd76a21c5
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.690Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0038', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-09-04T14:24:32.065476Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:ibm:xlock:*:*:*:*:*:*:*:*'], 'vendor': 'ibm', 'product': 'xlock', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-120', 'description': "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-09-04T14:07:08.502Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in xlock program allows local users to execute commands as root.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:29:31.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0038', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in xlock program allows local users to execute commands as root.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0038', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0038', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-12T14:37:48.860Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-1657
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
none
yes
partial
2.0.3
2025-01-16 21:06:18.971030+03:00
['CWE-916']
2025-01-16 21:04:24.473000+03:00
b7b50240e6fca9df17ab4aeb1f9fedb3016abaa237250356f993df0656ffcd71
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/20215', 'name': 'postgresql-md5-salt-weak-security(20215)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111402558115859&w=2', 'name': '20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111403050902165&w=2', 'name': '20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://archives.postgresql.org/pgsql-admin/2002-08/msg00253.php', 'name': '[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:34:55.633Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1657', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T18:06:18.971030Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-916', 'description': 'CWE-916 Use of Password Hash With Insufficient Computational Effort'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:04:24.473Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-08-21T04:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/20215', 'name': 'postgresql-md5-salt-weak-security(20215)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://marc.info/?l=bugtraq&m=111402558115859&w=2', 'name': '20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=111403050902165&w=2', 'name': '20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://archives.postgresql.org/pgsql-admin/2002-08/msg00253.php', 'name': '[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)', 'tags': ['mailing-list', 'x_refsource_MLIST']}], 'descriptions': [{'lang': 'en', 'value': 'PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/20215', 'name': 'postgresql-md5-salt-weak-security(20215)', 'refsource': 'XF'}, {'url': 'http://marc.info/?l=bugtraq&m=111402558115859&w=2', 'name': '20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=111403050902165&w=2', 'name': '20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords', 'refsource': 'BUGTRAQ'}, {'url': 'http://archives.postgresql.org/pgsql-admin/2002-08/msg00253.php', 'name': '[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)', 'refsource': 'MLIST'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1657', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1657', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:07:04.776Z', 'dateReserved': '2005-04-22T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-04-22T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2001-0667
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
no
partial
2.0.3
2025-01-16 19:14:19.075236+03:00
['CWE-88']
2025-01-16 19:13:31.088000+03:00
b38ae22eba25006217d7d26745df2bbec721079fa004d3b3e06eed883202a2a8
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.kb.cert.org/vuls/id/952611', 'name': 'VU#952611', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051', 'name': 'MS01-051', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7260', 'name': 'ie-telnet-command-execution-variant(7260)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.ciac.org/ciac/bulletins/m-024.shtml', 'name': 'M-024', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:30:06.104Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0667', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T16:14:19.075236Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-88', 'description': "CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T16:13:31.088Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-10-10T04:00:00.000Z', 'references': [{'url': 'http://www.kb.cert.org/vuls/id/952611', 'name': 'VU#952611', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051', 'name': 'MS01-051', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7260', 'name': 'ie-telnet-command-execution-variant(7260)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.ciac.org/ciac/bulletins/m-024.shtml', 'name': 'M-024', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC']}], 'descriptions': [{'lang': 'en', 'value': 'Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2002-03-01T15:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.kb.cert.org/vuls/id/952611', 'name': 'VU#952611', 'refsource': 'CERT-VN'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051', 'name': 'MS01-051', 'refsource': 'MS'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7260', 'name': 'ie-telnet-command-execution-variant(7260)', 'refsource': 'XF'}, {'url': 'http://www.ciac.org/ciac/bulletins/m-024.shtml', 'name': 'M-024', 'refsource': 'CIAC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0667', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0667', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T16:14:40.211Z', 'dateReserved': '2001-08-15T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-03-09T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0035
5.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
none
no
partial
2.0.3
2025-10-20 20:43:58.080852+03:00
['CWE-364']
2025-09-24 21:45:05.945000+03:00
fd915780738e647a91db45885e1ab2e6b131bd57f295f0a918f73d9fd3ddb8e1
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.758Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0035', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-10-20T17:43:58.080852Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-364', 'description': 'CWE-364 Signal Handler Race Condition'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-09-24T18:45:05.945Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:28:56.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0035', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0035', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0035', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-20T17:45:44.427Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-0254
3.70
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
none
no
partial
2.0.3
2025-01-16 20:54:18.251124+03:00
['CWE-434']
2025-01-16 20:53:56.131000+03:00
535bba59d0e8286c0dd947896fd1f0da0c96f6e04cb8e6adf0f5c129b0541ce8
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/12583', 'name': '12583', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=110868948719773&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=full-disclosure&m=110864983905770&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_FULLDISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:05:25.478Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-0254', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:54:18.251124Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-434', 'description': 'CWE-434 Unrestricted Upload of File with Dangerous Type'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:53:56.131Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-02-17T05:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/12583', 'name': '12583', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://marc.info/?l=bugtraq&m=110868948719773&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=full-disclosure&m=110864983905770&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'tags': ['mailing-list', 'x_refsource_FULLDISC']}], 'descriptions': [{'lang': 'en', 'value': 'BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/12583', 'name': '12583', 'refsource': 'BID'}, {'url': 'http://marc.info/?l=bugtraq&m=110868948719773&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=full-disclosure&m=110864983905770&w=2', 'name': '20050217 Advisory: Multiple Vulnerabilities in BibORB', 'refsource': 'FULLDISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-0254', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-0254', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:54:22.288Z', 'dateReserved': '2005-02-09T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-02-17T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-0747
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-02-06 00:31:51.729461+03:00
['CWE-131']
2025-01-16 20:45:17.631000+03:00
b2a44571032d943be65a3cc2c56679fa0011e44730fdf82e269d02d5e7c0cdfb
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2004_32_apache2.html', 'name': 'SUSE-SA:2004:032', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-463.html', 'name': 'RHSA-2004:463', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17384', 'name': 'apache-env-configuration-bo(17384)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2009/1233', 'name': 'ADV-2009-1233', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://secunia.com/advisories/12540', 'name': '12540', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561', 'name': 'oval:org.mitre.oval:def:11561', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://secunia.com/advisories/34920', 'name': '34920', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.trustix.org/errata/2004/0047/', 'name': '2004-0047', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX', 'x_transferred']}, {'url': 'http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096', 'name': 'MDKSA-2004:096', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml', 'name': 'GLSA-200409-21', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/481998', 'name': 'VU#481998', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1011303', 'name': '1011303', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210422 svn commit: r1074079 [2/3] - in /websites/staging/httpd/trunk/content: ./ apreq/ contribute/ contributors/ dev/ docs-project/ docs/ info/ mod_fcgid/ mod_ftp/ mod_mbox/ mod_smtpd/ modules/ security/ test/ test/flood/', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:31:46.612Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0747', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-05T21:31:51.729461Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-131', 'description': 'CWE-131 Incorrect Calculation of Buffer Size'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:45:17.631Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-09-15T00:00:00.000Z', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2004_32_apache2.html', 'name': 'SUSE-SA:2004:032', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-463.html', 'name': 'RHSA-2004:463', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17384', 'name': 'apache-env-configuration-bo(17384)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.vupen.com/english/advisories/2009/1233', 'name': 'ADV-2009-1233', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://secunia.com/advisories/12540', 'name': '12540', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561', 'name': 'oval:org.mitre.oval:def:11561', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://secunia.com/advisories/34920', 'name': '34920', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.trustix.org/errata/2004/0047/', 'name': '2004-0047', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX']}, {'url': 'http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096', 'name': 'MDKSA-2004:096', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml', 'name': 'GLSA-200409-21', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'http://www.kb.cert.org/vuls/id/481998', 'name': 'VU#481998', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://securitytracker.com/id?1011303', 'name': '1011303', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210422 svn commit: r1074079 [2/3] - in /websites/staging/httpd/trunk/content: ./ apreq/ contribute/ contributors/ dev/ docs-project/ docs/ info/ mod_fcgid/ mod_ftp/ mod_mbox/ mod_smtpd/ modules/ security/ test/ test/flood/', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'tags': ['mailing-list', 'x_refsource_MLIST']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2021-06-06T10:08:59.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.novell.com/linux/security/advisories/2004_32_apache2.html', 'name': 'SUSE-SA:2004:032', 'refsource': 'SUSE'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-463.html', 'name': 'RHSA-2004:463', 'refsource': 'REDHAT'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17384', 'name': 'apache-env-configuration-bo(17384)', 'refsource': 'XF'}, {'url': 'http://www.vupen.com/english/advisories/2009/1233', 'name': 'ADV-2009-1233', 'refsource': 'VUPEN'}, {'url': 'http://secunia.com/advisories/12540', 'name': '12540', 'refsource': 'SECUNIA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11561', 'name': 'oval:org.mitre.oval:def:11561', 'refsource': 'OVAL'}, {'url': 'http://secunia.com/advisories/34920', 'name': '34920', 'refsource': 'SECUNIA'}, {'url': 'http://www.trustix.org/errata/2004/0047/', 'name': '2004-0047', 'refsource': 'TRUSTIX'}, {'url': 'http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096', 'name': 'MDKSA-2004:096', 'refsource': 'MANDRAKE'}, {'url': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'name': 'http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147', 'refsource': 'MISC'}, {'url': 'http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml', 'name': 'GLSA-200409-21', 'refsource': 'GENTOO'}, {'url': 'http://www.kb.cert.org/vuls/id/481998', 'name': 'VU#481998', 'refsource': 'CERT-VN'}, {'url': 'http://securitytracker.com/id?1011303', 'name': '1011303', 'refsource': 'SECTRACK'}, {'url': 'https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [4/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210422 svn commit: r1074079 [2/3] - in /websites/staging/httpd/trunk/content: ./ apreq/ contribute/ contributors/ dev/ docs-project/ docs/ info/ mod_fcgid/ mod_ftp/ mod_mbox/ mod_smtpd/ modules/ security/ test/ test/flood/', 'refsource': 'MLIST'}, {'url': 'https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6@%3Ccvs.httpd.apache.org%3E', 'name': '[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html', 'refsource': 'MLIST'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0747', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0747', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:47:15.175Z', 'dateReserved': '2004-07-26T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-17T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0012
7.00
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
none
no
partial
2.0.3
2025-04-07 21:20:15.808307+03:00
['CWE-290']
2025-04-09 20:48:23.039000+03:00
8fab048d9db45ceca23c664bea3547e8ac9b2fb027bd0c90a9a3fa8cf072f7f4
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.462Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0012', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-07T18:20:15.808307Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-290', 'description': 'CWE-290 Authentication Bypass by Spoofing'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-09T17:48:23.039Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:24:34.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0012', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0012', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0012', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-09T18:30:54.684Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0041
none
no
partial
2.0.3
2024-09-04 17:09:51.440131+03:00
2024-09-17 17:25:12.391000+03:00
6b240a78ad9ab7b7b2a82a55b85dedd2d320f76f21651b4f51283fe03aeafb9d
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.067Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0041', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-09-04T14:09:51.440131Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-09-17T14:25:12.391Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in NLS (Natural Language Service).'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:30:20.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0041', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in NLS (Natural Language Service).'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0041', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0041', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-17T14:25:15.473Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0632
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
partial
2.0.3
2026-05-28 20:48:11.820577+03:00
['CWE-200']
2026-05-28 20:48:04.805000+03:00
e5c17bac10512543e0778c0b33c1865ff0517c06e3f118c2e27f002ded98a316
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:41:45.686Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0632', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:48:11.820577Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:48:04.805Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'The RPC portmapper service is running.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T08:29:40.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'name': 'https://www.cve.org/CVERecord?id=CVE-1999-0632', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The RPC portmapper service is running.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0632', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0632', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:48:17.662Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-1999-0069
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-08-01 22:51:45.938973+03:00
['CWE-119']
2024-08-01 22:52:53.361000+03:00
47927784c94226c779dd95f8e3f3edc38eb13bd33ceb7ccd63b522e9460fde4c
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/8158', 'name': '8158', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169', 'name': '00169', 'tags': ['vendor-advisory', 'x_refsource_SUN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.100Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0069', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:51:45.938973Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sun:sunos:5.5:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'sunos', 'versions': [{'status': 'affected', 'version': '5.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'sunos', 'versions': [{'status': 'affected', 'version': '5.5.1'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-119', 'description': 'CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:52:53.361Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/8158', 'name': '8158', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169', 'name': '00169', 'tags': ['vendor-advisory', 'x_refsource_SUN']}], 'descriptions': [{'lang': 'en', 'value': 'Solaris ufsrestore buffer overflow.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2004-09-02T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/8158', 'name': '8158', 'refsource': 'OSVDB'}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169', 'name': '00169', 'refsource': 'SUN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Solaris ufsrestore buffer overflow.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0069', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0069', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T19:55:25.041Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-2761
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2026-05-28 21:20:04.495874+03:00
['CWE-328']
2026-05-28 21:19:58.612000+03:00
0a43c238d2c8e0c0168349844018df82434fbcffa267bbf61ebf47af52c6aae6
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/33065', 'name': '33065', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0837.html', 'name': 'RHSA-2010:0837', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.phreedom.org/research/rogue-ca/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/836068', 'name': 'VU#836068', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://securityreason.com/securityalert/4866', 'name': '4866', 'tags': ['third-party-advisory', 'x_refsource_SREASON', 'x_transferred']}, {'url': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html', 'name': '20090115 MD5 Hashes May Allow for Certificate Spoofing', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://secunia.com/advisories/33826', 'name': '33826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/34281', 'name': '34281', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0838.html', 'name': 'RHSA-2010:0838', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-740-1', 'name': 'USN-740-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1024697', 'name': '1024697', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html', 'name': 'FEDORA-2009-1276', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/499685/100/0/threaded', 'name': '20081230 MD5 Considered Harmful Today: Creating a rogue CA certificate', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://secunia.com/advisories/42181', 'name': '42181', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:36:25.448Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2761', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-28T18:20:04.495874Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-328', 'description': 'CWE-328 Use of Weak Hash'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T18:19:58.612Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-08-17T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/33065', 'name': '33065', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0837.html', 'name': 'RHSA-2010:0837', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.phreedom.org/research/rogue-ca/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.kb.cert.org/vuls/id/836068', 'name': 'VU#836068', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://securityreason.com/securityalert/4866', 'name': '4866', 'tags': ['third-party-advisory', 'x_refsource_SREASON']}, {'url': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html', 'name': '20090115 MD5 Hashes May Allow for Certificate Spoofing', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'tags': ['x_refsource_MISC']}, {'url': 'http://secunia.com/advisories/33826', 'name': '33826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/34281', 'name': '34281', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'tags': ['x_refsource_MISC']}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'tags': ['x_refsource_MISC']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC']}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0838.html', 'name': 'RHSA-2010:0838', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.ubuntu.com/usn/usn-740-1', 'name': 'USN-740-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://securitytracker.com/id?1024697', 'name': '1024697', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html', 'name': 'FEDORA-2009-1276', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/archive/1/499685/100/0/threaded', 'name': '20081230 MD5 Considered Harmful Today: Creating a rogue CA certificate', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://secunia.com/advisories/42181', 'name': '42181', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'tags': ['x_refsource_MISC']}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/33065', 'name': '33065', 'refsource': 'BID'}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0837.html', 'name': 'RHSA-2010:0837', 'refsource': 'REDHAT'}, {'url': 'http://www.phreedom.org/research/rogue-ca/', 'name': 'http://www.phreedom.org/research/rogue-ca/', 'refsource': 'MISC'}, {'url': 'http://www.kb.cert.org/vuls/id/836068', 'name': 'VU#836068', 'refsource': 'CERT-VN'}, {'url': 'http://securityreason.com/securityalert/4866', 'name': '4866', 'refsource': 'SREASON'}, {'url': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'name': 'http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/', 'refsource': 'MISC'}, {'url': 'http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html', 'name': '20090115 MD5 Hashes May Allow for Certificate Spoofing', 'refsource': 'CISCO'}, {'url': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'name': 'http://www.win.tue.nl/hashclash/SoftIntCodeSign/', 'refsource': 'MISC'}, {'url': 'http://secunia.com/advisories/33826', 'name': '33826', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/34281', 'name': '34281', 'refsource': 'SECUNIA'}, {'url': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'name': 'http://www.microsoft.com/technet/security/advisory/961509.mspx', 'refsource': 'MISC'}, {'url': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'name': 'https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us', 'refsource': 'CONFIRM'}, {'url': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'name': 'http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx', 'refsource': 'MISC'}, {'url': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'name': 'http://www.doxpara.com/research/md5/md5_someday.pdf', 'refsource': 'MISC'}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'name': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'refsource': 'MISC'}, {'url': 'https://rhn.redhat.com/errata/RHSA-2010-0838.html', 'name': 'RHSA-2010:0838', 'refsource': 'REDHAT'}, {'url': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'name': 'https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php', 'refsource': 'MISC'}, {'url': 'http://www.ubuntu.com/usn/usn-740-1', 'name': 'USN-740-1', 'refsource': 'UBUNTU'}, {'url': 'http://securitytracker.com/id?1024697', 'name': '1024697', 'refsource': 'SECTRACK'}, {'url': 'https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html', 'name': 'FEDORA-2009-1276', 'refsource': 'FEDORA'}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'name': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888', 'refsource': 'CONFIRM'}, {'url': 'http://www.securityfocus.com/archive/1/499685/100/0/threaded', 'name': '20081230 MD5 Considered Harmful Today: Creating a rogue CA certificate', 'refsource': 'BUGTRAQ'}, {'url': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'name': 'https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935', 'refsource': 'CONFIRM'}, {'url': 'http://secunia.com/advisories/42181', 'name': '42181', 'refsource': 'SECUNIA'}, {'url': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'name': 'http://www.win.tue.nl/hashclash/rogue-ca/', 'refsource': 'MISC'}, {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=648886', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2761', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2761', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T18:20:09.605Z', 'dateReserved': '2009-01-05T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2009-01-05T20:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-2004-0458
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2025-01-16 20:35:36.151205+03:00
['CWE-476']
2025-01-16 20:35:16.531000+03:00
e59308d0604c56007cad57371c6cd951b23287d697e519dd626aeb39c3711b40
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/10343', 'name': '10343', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16143', 'name': 'mah-jong-null-dos(16143)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.debian.org/security/2004/dsa-503', 'name': 'DSA-503', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:17:14.961Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0458', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:35:36.151205Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-476', 'description': 'CWE-476 NULL Pointer Dereference'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:35:16.531Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-05-13T04:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/10343', 'name': '10343', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16143', 'name': 'mah-jong-null-dos(16143)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.debian.org/security/2004/dsa-503', 'name': 'DSA-503', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}], 'descriptions': [{'lang': 'en', 'value': 'mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/10343', 'name': '10343', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16143', 'name': 'mah-jong-null-dos(16143)', 'refsource': 'XF'}, {'url': 'http://www.debian.org/security/2004/dsa-503', 'name': 'DSA-503', 'refsource': 'DEBIAN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0458', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0458', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:35:50.721Z', 'dateReserved': '2004-05-10T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-08-19T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0052
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2024-08-01 23:17:55.821578+03:00
['CWE-476']
2024-08-01 23:32:02.473000+03:00
b37b68456ab57169a17b3c9cfa48d6fb9836857eb6ce252fcf62d9331a2527a3
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1389', 'name': 'freebsd-ip-frag-dos(1389)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.osvdb.org/908', 'name': '908', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.172Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0052', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:17:55.821578Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:bsdi:bsd_os:4.0:*:*:*:*:*:*:*'], 'vendor': 'bsdi', 'product': 'bsd_os', 'versions': [{'status': 'affected', 'version': '4.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:1.1.5.1:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '1.1.5.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0.5:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.5:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.6:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.6'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.7.1:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.7.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.2.2:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.2.2'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.2.8:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.2.8'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:openbsd:openbsd:2.2:*:*:*:*:*:*:*'], 'vendor': 'openbsd', 'product': 'openbsd', 'versions': [{'status': 'affected', 'version': '2.2'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:openbsd:openbsd:2.3:*:*:*:*:*:*:*'], 'vendor': 'openbsd', 'product': 'openbsd', 'versions': [{'status': 'affected', 'version': '2.3'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:openbsd:openbsd:2.4:*:*:*:*:*:*:*'], 'vendor': 'openbsd', 'product': 'openbsd', 'versions': [{'status': 'affected', 'version': '2.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-476', 'description': 'CWE-476 NULL Pointer Dereference'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:32:02.473Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1389', 'name': 'freebsd-ip-frag-dos(1389)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.osvdb.org/908', 'name': '908', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-12-18T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1389', 'name': 'freebsd-ip-frag-dos(1389)', 'refsource': 'XF'}, {'url': 'http://www.osvdb.org/908', 'name': '908', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0052', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0052', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:32:09.970Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2001-0006
none
no
partial
2.0.3
2024-01-31 18:50:22.565040+03:00
2024-12-03 18:42:59.652000+03:00
0d37e68025df49b832871d6d2eb211fbc7917bed1b63aac0ba8bfaa1af242452
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=98075221915234&w=2', 'name': '20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003', 'name': 'MS01-003', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6006', 'name': 'winnt-mutex-dos(6006)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:06:54.497Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0006', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-31T15:50:22.565040Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-12-03T15:42:59.652Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-01-24T05:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=98075221915234&w=2', 'name': '20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003', 'name': 'MS01-003', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6006', 'name': 'winnt-mutex-dos(6006)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T15:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=98075221915234&w=2', 'name': '20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below', 'refsource': 'BUGTRAQ'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003', 'name': 'MS01-003', 'refsource': 'MS'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6006', 'name': 'winnt-mutex-dos(6006)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0006', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0006', 'state': 'PUBLISHED', 'dateUpdated': '2024-12-03T15:43:09.651Z', 'dateReserved': '2001-01-04T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-05-07T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-0391
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-02-08 22:26:07.645774+03:00
['CWE-190']
2025-01-16 20:13:54.722000+03:00
66d306658d187d8921c839a07d648e6b8e569b6523715638d105472347c7a680
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.iss.net/security_center/static/9170.php', 'name': 'sunrpc-xdr-array-bo(9170)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A', 'name': '20020801-01-A', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://www.cert.org/advisories/CA-2002-25.html', 'name': 'CA-2002-25', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://online.securityfocus.com/advisories/4402', 'name': 'HPSBTL0208-061', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=103158632831416&w=2', 'name': '20020909 GLSA: glibc', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-146', 'name': 'DSA-146', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-166.html', 'name': 'RHSA-2002:166', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/hp/2002-q3/0077.html', 'name': 'HPSBUX0209-215', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt', 'name': 'CSSA-2002-055.0', 'tags': ['vendor-advisory', 'x_refsource_CALDERA', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-143', 'name': 'DSA-143', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['third-party-advisory', 'x_refsource_ISS', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P', 'name': '20020801-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515', 'name': 'CLA-2002:515', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535', 'name': 'CLA-2002:535', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-212.html', 'name': 'RHSA-2003:212', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057', 'name': 'MS02-057', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-142', 'name': 'DSA-142', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc', 'name': 'NetBSD-SA2002-011', 'tags': ['vendor-advisory', 'x_refsource_NETBSD', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/aix/2002-q4/0002.html', 'name': 'IY34194', 'tags': ['vendor-advisory', 'x_refsource_AIXAPAR', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-167.html', 'name': 'RHSA-2002:167', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html', 'name': '20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102821928418261&w=2', 'name': 'FreeBSD-SA-02:34.rpc', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-173.html', 'name': 'RHSA-2002:173', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/5356', 'name': '5356', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://online.securityfocus.com/archive/1/285740', 'name': '20020802 kerberos rpc xdr_array', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102813809232532&w=2', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102821785316087&w=2', 'name': '20020801 RPC analysis', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/192995', 'name': 'VU#192995', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-172.html', 'name': 'RHSA-2002:172', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728', 'name': 'oval:org.mitre.oval:def:4728', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42', 'name': 'oval:org.mitre.oval:def:42', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.linuxsecurity.com/advisories/other_advisory-2399.html', 'name': 'ESA-20021003-021', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9', 'name': 'oval:org.mitre.oval:def:9', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057', 'name': 'MDKSA-2002:057', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://www.debian.org/security/2002/dsa-149', 'name': 'DSA-149', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=102831443208382&w=2', 'name': '20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.debian.org/security/2003/dsa-333', 'name': 'DSA-333', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-168.html', 'name': 'RHSA-2003:168', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:49:28.492Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0391', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-08T19:26:07.645774Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-190', 'description': 'CWE-190 Integer Overflow or Wraparound'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:13:54.722Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-07-29T00:00:00.000Z', 'references': [{'url': 'http://www.iss.net/security_center/static/9170.php', 'name': 'sunrpc-xdr-array-bo(9170)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A', 'name': '20020801-01-A', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://www.cert.org/advisories/CA-2002-25.html', 'name': 'CA-2002-25', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://online.securityfocus.com/advisories/4402', 'name': 'HPSBTL0208-061', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://marc.info/?l=bugtraq&m=103158632831416&w=2', 'name': '20020909 GLSA: glibc', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.debian.org/security/2002/dsa-146', 'name': 'DSA-146', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-166.html', 'name': 'RHSA-2002:166', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://archives.neohapsis.com/archives/hp/2002-q3/0077.html', 'name': 'HPSBUX0209-215', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt', 'name': 'CSSA-2002-055.0', 'tags': ['vendor-advisory', 'x_refsource_CALDERA']}, {'url': 'http://www.debian.org/security/2002/dsa-143', 'name': 'DSA-143', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['third-party-advisory', 'x_refsource_ISS']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P', 'name': '20020801-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515', 'name': 'CLA-2002:515', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535', 'name': 'CLA-2002:535', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-212.html', 'name': 'RHSA-2003:212', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057', 'name': 'MS02-057', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.debian.org/security/2002/dsa-142', 'name': 'DSA-142', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc', 'name': 'NetBSD-SA2002-011', 'tags': ['vendor-advisory', 'x_refsource_NETBSD']}, {'url': 'http://archives.neohapsis.com/archives/aix/2002-q4/0002.html', 'name': 'IY34194', 'tags': ['vendor-advisory', 'x_refsource_AIXAPAR']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-167.html', 'name': 'RHSA-2002:167', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html', 'name': '20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=102821928418261&w=2', 'name': 'FreeBSD-SA-02:34.rpc', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-173.html', 'name': 'RHSA-2002:173', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.securityfocus.com/bid/5356', 'name': '5356', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://online.securityfocus.com/archive/1/285740', 'name': '20020802 kerberos rpc xdr_array', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=102813809232532&w=2', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=102821785316087&w=2', 'name': '20020801 RPC analysis', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.kb.cert.org/vuls/id/192995', 'name': 'VU#192995', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-172.html', 'name': 'RHSA-2002:172', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728', 'name': 'oval:org.mitre.oval:def:4728', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42', 'name': 'oval:org.mitre.oval:def:42', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.linuxsecurity.com/advisories/other_advisory-2399.html', 'name': 'ESA-20021003-021', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9', 'name': 'oval:org.mitre.oval:def:9', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057', 'name': 'MDKSA-2002:057', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://www.debian.org/security/2002/dsa-149', 'name': 'DSA-149', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://marc.info/?l=bugtraq&m=102831443208382&w=2', 'name': '20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.debian.org/security/2003/dsa-333', 'name': 'DSA-333', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-168.html', 'name': 'RHSA-2003:168', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}], 'descriptions': [{'lang': 'en', 'value': 'Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2003-03-20T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.iss.net/security_center/static/9170.php', 'name': 'sunrpc-xdr-array-bo(9170)', 'refsource': 'XF'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A', 'name': '20020801-01-A', 'refsource': 'SGI'}, {'url': 'http://www.cert.org/advisories/CA-2002-25.html', 'name': 'CA-2002-25', 'refsource': 'CERT'}, {'url': 'http://online.securityfocus.com/advisories/4402', 'name': 'HPSBTL0208-061', 'refsource': 'HP'}, {'url': 'http://marc.info/?l=bugtraq&m=103158632831416&w=2', 'name': '20020909 GLSA: glibc', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.debian.org/security/2002/dsa-146', 'name': 'DSA-146', 'refsource': 'DEBIAN'}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-166.html', 'name': 'RHSA-2002:166', 'refsource': 'REDHAT'}, {'url': 'http://archives.neohapsis.com/archives/hp/2002-q3/0077.html', 'name': 'HPSBUX0209-215', 'refsource': 'HP'}, {'url': 'ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt', 'name': 'CSSA-2002-055.0', 'refsource': 'CALDERA'}, {'url': 'http://www.debian.org/security/2002/dsa-143', 'name': 'DSA-143', 'refsource': 'DEBIAN'}, {'url': 'http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'refsource': 'ISS'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P', 'name': '20020801-01-P', 'refsource': 'SGI'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515', 'name': 'CLA-2002:515', 'refsource': 'CONECTIVA'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535', 'name': 'CLA-2002:535', 'refsource': 'CONECTIVA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-212.html', 'name': 'RHSA-2003:212', 'refsource': 'REDHAT'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-057', 'name': 'MS02-057', 'refsource': 'MS'}, {'url': 'http://www.debian.org/security/2002/dsa-142', 'name': 'DSA-142', 'refsource': 'DEBIAN'}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc', 'name': 'NetBSD-SA2002-011', 'refsource': 'NETBSD'}, {'url': 'http://archives.neohapsis.com/archives/aix/2002-q4/0002.html', 'name': 'IY34194', 'refsource': 'AIXAPAR'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-167.html', 'name': 'RHSA-2002:167', 'refsource': 'REDHAT'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html', 'name': '20020803 OpenAFS Security Advisory 2002-001: Remote root vulnerability in OpenAFS servers', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=102821928418261&w=2', 'name': 'FreeBSD-SA-02:34.rpc', 'refsource': 'FREEBSD'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-173.html', 'name': 'RHSA-2002:173', 'refsource': 'REDHAT'}, {'url': 'http://www.securityfocus.com/bid/5356', 'name': '5356', 'refsource': 'BID'}, {'url': 'http://online.securityfocus.com/archive/1/285740', 'name': '20020802 kerberos rpc xdr_array', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=102813809232532&w=2', 'name': '20020731 Remote Buffer Overflow Vulnerability in Sun RPC', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=102821785316087&w=2', 'name': '20020801 RPC analysis', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.kb.cert.org/vuls/id/192995', 'name': 'VU#192995', 'refsource': 'CERT-VN'}, {'url': 'http://rhn.redhat.com/errata/RHSA-2002-172.html', 'name': 'RHSA-2002:172', 'refsource': 'REDHAT'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4728', 'name': 'oval:org.mitre.oval:def:4728', 'refsource': 'OVAL'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A42', 'name': 'oval:org.mitre.oval:def:42', 'refsource': 'OVAL'}, {'url': 'http://www.linuxsecurity.com/advisories/other_advisory-2399.html', 'name': 'ESA-20021003-021', 'refsource': 'ENGARDE'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9', 'name': 'oval:org.mitre.oval:def:9', 'refsource': 'OVAL'}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:057', 'name': 'MDKSA-2002:057', 'refsource': 'MANDRAKE'}, {'url': 'http://www.debian.org/security/2002/dsa-149', 'name': 'DSA-149', 'refsource': 'DEBIAN'}, {'url': 'http://marc.info/?l=bugtraq&m=102831443208382&w=2', 'name': '20020802 MITKRB5-SA-2002-001: Remote root vulnerability in MIT krb5 admin', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.debian.org/security/2003/dsa-333', 'name': 'DSA-333', 'refsource': 'DEBIAN'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-168.html', 'name': 'RHSA-2003:168', 'refsource': 'REDHAT'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0391', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0391', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:20:45.514Z', 'dateReserved': '2002-05-28T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2003-04-02T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-0485
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
none
yes
partial
2.0.3
2024-02-05 20:19:31.934437+03:00
['CWE-178']
2025-01-16 20:05:45.659000+03:00
14b9a01b0305c220cbca68e56dead72dfd739e24cf69641bf3162cd9983a0e37
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=vuln-dev&m=101681724810317&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_VULN-DEV', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=101684260510079&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:49:28.482Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0485', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-05T17:19:31.934437Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-178', 'description': 'CWE-178 Improper Handling of Case Sensitivity'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:05:45.659Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-03-22T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=vuln-dev&m=101681724810317&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_VULN-DEV']}, {'url': 'http://marc.info/?l=bugtraq&m=101684260510079&w=2', 'name': '20020322 One more way to bypass NAV', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T13:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=vuln-dev&m=101681724810317&w=2', 'name': '20020322 One more way to bypass NAV', 'refsource': 'VULN-DEV'}, {'url': 'http://marc.info/?l=bugtraq&m=101684260510079&w=2', 'name': '20020322 One more way to bypass NAV', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0485', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0485', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:07:29.547Z', 'dateReserved': '2002-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-06-11T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0011
5.40
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
none
no
partial
2.0.3
2025-04-07 21:22:05.623556+03:00
['CWE-1067']
2025-04-07 21:56:08.140000+03:00
b52d33ed400f05cc5ae219e38504225b3e2e9e97b67a980529d018eb391c0006
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX', 'name': '19980603-01-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083', 'name': 'HPSBUX9808-083', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180', 'name': '00180', 'tags': ['vendor-advisory', 'x_refsource_SUN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.479Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0011', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-07T18:22:05.623556Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-1067', 'description': 'CWE-1067 Excessive Execution of Sequential Searches of Data Resource'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-07T18:56:08.140Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX', 'name': '19980603-01-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083', 'name': 'HPSBUX9808-083', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180', 'name': '00180', 'tags': ['vendor-advisory', 'x_refsource_SUN']}], 'descriptions': [{'lang': 'en', 'value': 'Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2009-03-02T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX', 'name': '19980603-01-PX', 'refsource': 'SGI'}, {'url': 'http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083', 'name': 'HPSBUX9808-083', 'refsource': 'HP'}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180', 'name': '00180', 'refsource': 'SUN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0011', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0011', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-09T18:29:26.012Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-2339
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-03-21 19:25:19.376306+03:00
2025-01-16 22:37:51.415000+03:00
a9447edbd90cb0b532cfaaeecc51cdf117276f1b18d4fd53e5677a0293d35af9
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securitytracker.com/id?1009128', 'name': '1009128', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/354392', 'name': '20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15263', 'name': 'win-kernel-gain-privileges(15263)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:22:13.688Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2339', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-03-21T16:25:19.376306Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:37:51.415Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-02-18T05:00:00.000Z', 'references': [{'url': 'http://www.securitytracker.com/id?1009128', 'name': '1009128', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/354392', 'name': '20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15263', 'name': 'win-kernel-gain-privileges(15263)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securitytracker.com/id?1009128', 'name': '1009128', 'refsource': 'SECTRACK'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/354392', 'name': '20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'refsource': 'BUGTRAQ'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html', 'name': '20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges', 'refsource': 'BUGTRAQ'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15263', 'name': 'win-kernel-gain-privileges(15263)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2339', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2339', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:40:39.858Z', 'dateReserved': '2005-08-16T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-08-16T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2001-1546
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2025-01-16 22:32:50.230975+03:00
['CWE-326']
2025-01-16 22:32:39.530000+03:00
af26f55d6ff9cf675c76b78c0c12eb71961cc070742e4c71aee353a01b69a62c
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.iss.net/security_center/static/7682.php', 'name': 'pathways-homecare-weak-encryption(7682)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/3653', 'name': '3653', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/244367', 'name': '20011207 Weak Encryption Vulnerability in Pathways Homecare', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:58:11.457Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-1546', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:32:50.230975Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-326', 'description': 'CWE-326 Inadequate Encryption Strength'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:32:39.530Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.iss.net/security_center/static/7682.php', 'name': 'pathways-homecare-weak-encryption(7682)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/bid/3653', 'name': '3653', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.securityfocus.com/archive/1/244367', 'name': '20011207 Weak Encryption Vulnerability in Pathways Homecare', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-14T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.iss.net/security_center/static/7682.php', 'name': 'pathways-homecare-weak-encryption(7682)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/bid/3653', 'name': '3653', 'refsource': 'BID'}, {'url': 'http://www.securityfocus.com/archive/1/244367', 'name': '20011207 Weak Encryption Vulnerability in Pathways Homecare', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-1546', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-1546', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:33:06.252Z', 'dateReserved': '2005-07-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-1816
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-02-16 19:45:29.048974+03:00
['CWE-193']
2025-01-16 22:26:18.368000+03:00
aa5b2d5375a5a8f49d7210672dc4d0ef3db1b83cbecbc3e3e187651a5d2e5289
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/5956', 'name': '5956', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/7293', 'name': '7293', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-10/0187.html', 'name': '20021012 Pyramid Research Project - atphttpd security advisorie', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/10362.php', 'name': 'atphttpd-sockgets-bo(10362)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:43:32.518Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1816', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-16T16:45:29.048974Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-193', 'description': 'CWE-193 Off-by-one Error'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:26:18.368Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-10-12T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/5956', 'name': '5956', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/7293', 'name': '7293', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-10/0187.html', 'name': '20021012 Pyramid Research Project - atphttpd security advisorie', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.iss.net/security_center/static/10362.php', 'name': 'atphttpd-sockgets-bo(10362)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-06T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/5956', 'name': '5956', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/7293', 'name': '7293', 'refsource': 'SECUNIA'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2002-10/0187.html', 'name': '20021012 Pyramid Research Project - atphttpd security advisorie', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.iss.net/security_center/static/10362.php', 'name': 'atphttpd-sockgets-bo(10362)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1816', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1816', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:26:26.128Z', 'dateReserved': '2005-06-29T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-28T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-1588
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-08-01 21:55:51.139162+03:00
['CWE-119']
2024-08-01 22:00:04.677000+03:00
208c8f510808244c1aa598e887c3df6e471365accd6d0931632a7cbabc652426
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/2319', 'name': '2319', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T17:18:07.629Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-1588', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T18:55:51.139162Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sun:solaris:2.4:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '2.4'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:solaris:2.5:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '2.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:solaris:2.5.1:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '2.5.1'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-119', 'description': 'CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:00:04.677Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/2319', 'name': '2319', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'tags': ['x_refsource_MISC']}, {'url': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-04-21T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'name': 'http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/2319', 'name': '2319', 'refsource': 'BID'}, {'url': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'name': 'http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c', 'refsource': 'MISC'}, {'url': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'name': 'http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-1588', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-1588', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T18:19:09.412Z', 'dateReserved': '2006-04-21T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-04-21T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2001-1533
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
none
yes
partial
2.0.3
2024-03-21 18:57:24.602314+03:00
2025-01-16 22:29:07.567000+03:00
73098b1e449bd9894c25d57e4499a798aa15983566f2c50ce4bc8c3a5be252c9
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/3501', 'name': '3501', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/7446.php', 'name': 'isa-udp-flood-dos(7446)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html', 'name': '20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html', 'name': '20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:58:11.600Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-1533', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-03-21T15:57:24.602314Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:29:07.567Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/bid/3501', 'name': '3501', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.iss.net/security_center/static/7446.php', 'name': 'isa-udp-flood-dos(7446)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html', 'name': '20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html', 'name': '20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-14T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/3501', 'name': '3501', 'refsource': 'BID'}, {'url': 'http://www.iss.net/security_center/static/7446.php', 'name': 'isa-udp-flood-dos(7446)', 'refsource': 'XF'}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html', 'name': '20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'refsource': 'BUGTRAQ'}, {'url': 'http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html', 'name': '20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-1533', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-1533', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:29:17.831Z', 'dateReserved': '2005-07-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0524
4.00
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
none
no
partial
2.0.3
2026-05-28 20:44:13.487206+03:00
['CWE-200']
2026-05-28 20:44:09.438000+03:00
091571bc39272694d99c271ae6b2eb4ad1e7546ee1b399afcb768619c3e4d99c
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/322', 'name': 'icmp-timestamp(322)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://descriptions.securescout.com/tc/11010', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/306', 'name': 'icmp-netmask(306)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://descriptions.securescout.com/tc/11011', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/95', 'name': '95', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://support.f5.com/csp/article/K15277'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2025-03-17T15:03:25.141Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0524', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:44:13.487206Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:44:09.438Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/322', 'name': 'icmp-timestamp(322)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://descriptions.securescout.com/tc/11010', 'tags': ['x_refsource_MISC']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/306', 'name': 'icmp-netmask(306)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://descriptions.securescout.com/tc/11011', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/95', 'name': '95', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'tags': ['x_refsource_MISC']}, {'url': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/322', 'name': 'icmp-timestamp(322)', 'refsource': 'XF'}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'name': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10053', 'refsource': 'CONFIRM'}, {'url': 'http://descriptions.securescout.com/tc/11010', 'name': 'http://descriptions.securescout.com/tc/11010', 'refsource': 'MISC'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/306', 'name': 'icmp-netmask(306)', 'refsource': 'XF'}, {'url': 'http://descriptions.securescout.com/tc/11011', 'name': 'http://descriptions.securescout.com/tc/11011', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/95', 'name': '95', 'refsource': 'OSVDB'}, {'url': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'name': 'http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434', 'refsource': 'MISC'}, {'url': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'name': 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0524', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0524', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:44:18.231Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-1999-0511
9.10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
none
yes
total
2.0.3
2026-05-28 20:30:53.896976+03:00
['CWE-200']
2026-05-28 20:30:47.851000+03:00
653fcb3dcc7aec276c036f452a2e7a4aa63be418c25126efd90c5b9c5d1815a7
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:41:45.609Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0511', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:30:53.896976Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:30:47.851Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'IP forwarding is enabled on a machine which is not a router or firewall.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T08:26:28.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'name': 'https://www.cve.org/CVERecord?id=CVE-1999-0511', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IP forwarding is enabled on a machine which is not a router or firewall.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0511', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0511', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:30:57.864Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-1999-0006
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-08-01 21:51:01.909711+03:00
['CWE-125']
2024-08-01 21:53:30.423000+03:00
e2ab2c2809b0aecf3e0980ade206478b8e284f785dcf91938f8c554590a29c80
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I', 'name': '19980801-01-I', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/133', 'name': '133', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.465Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0006', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T18:51:01.909711Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:qualcomm:qpopper:2.4:*:*:*:*:*:*:*'], 'vendor': 'qualcomm', 'product': 'qpopper', 'versions': [{'status': 'affected', 'version': '2.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T18:53:30.423Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I', 'name': '19980801-01-I', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://www.securityfocus.com/bid/133', 'name': '133', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': "Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I', 'name': '19980801-01-I', 'refsource': 'SGI'}, {'url': 'http://www.securityfocus.com/bid/133', 'name': '133', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0006', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0006', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:08:55.394Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-1975
5.50
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
none
no
partial
2.0.3
2024-02-14 21:32:35.113838+03:00
['CWE-326']
2025-01-16 22:27:02.927000+03:00
8e45c83faa8a7c970158d4f4a0049c6c25f8b807c9c0bfea9b36d9c4761310c9
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://online.securityfocus.com/archive/1/281437', 'name': '20020710 Multiple Security Vulnerabilities in Sharp Zaurus', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/5201', 'name': '5201', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/9535.php', 'name': 'zaurus-passcode-weak-encryption(9535)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:43:33.674Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1975', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-14T18:32:35.113838Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-326', 'description': 'CWE-326 Inadequate Encryption Strength'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:27:02.927Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://online.securityfocus.com/archive/1/281437', 'name': '20020710 Multiple Security Vulnerabilities in Sharp Zaurus', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/5201', 'name': '5201', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.iss.net/security_center/static/9535.php', 'name': 'zaurus-passcode-weak-encryption(9535)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-06-28T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://online.securityfocus.com/archive/1/281437', 'name': '20020710 Multiple Security Vulnerabilities in Sharp Zaurus', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/5201', 'name': '5201', 'refsource': 'BID'}, {'url': 'http://www.iss.net/security_center/static/9535.php', 'name': 'zaurus-passcode-weak-encryption(9535)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1975', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1975', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:27:36.964Z', 'dateReserved': '2005-06-28T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-28T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0022
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-08-01 22:04:07.612814+03:00
['CWE-125']
2024-08-01 22:13:12.881000+03:00
663b230474c1db0d1ad38afabaa0063a97725bd123aa4a4db9b248374efc584f
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179', 'name': '00179', 'tags': ['vendor-advisory', 'x_refsource_SUN', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.096Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0022', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:04:07.612814Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:*:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.0'}, {'status': 'affected', 'version': '5.0.1'}, {'status': 'affected', 'version': '5.1'}, {'status': 'affected', 'version': '5.1.1'}, {'status': 'affected', 'version': '5.2'}, {'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '6.0'}, {'status': 'affected', 'version': '6.0.1'}, {'status': 'affected', 'version': '6.1'}, {'status': 'affected', 'version': '6.2'}, {'status': 'affected', 'version': '6.3'}, {'status': 'affected', 'version': '6.4'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sgi:irix:5.3:*:xfs:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.3'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sgi:irix:6.0.1:*:xfs:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '6.0.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:bsdi:bsd_os:1.1:*:*:*:*:*:*:*'], 'vendor': 'bsdi', 'product': 'bsd_os', 'versions': [{'status': 'affected', 'version': '1.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.0.5:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.0.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:freebsd:freebsd:2.1.0:*:*:*:*:*:*:*'], 'vendor': 'freebsd', 'product': 'freebsd', 'versions': [{'status': 'affected', 'version': '2.1.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:hp:hp-ux:10.00:*:*:*:*:*:*:*'], 'vendor': 'hp', 'product': 'hp-ux', 'versions': [{'status': 'affected', 'version': '10.00'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:ibm:aix:3.1:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:3.2:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:3.2.4:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:3.2.5:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.2:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.3:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.4:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.1.5:*:*:*:*:*:*:*', 'cpe:2.3:o:ibm:aix:4.2:*:*:*:*:*:*:*'], 'vendor': 'ibm', 'product': 'aix', 'versions': [{'status': 'affected', 'version': '3.1'}, {'status': 'affected', 'version': '3.2'}, {'status': 'affected', 'version': '3.2.4'}, {'status': 'affected', 'version': '3.2.5'}, {'status': 'affected', 'version': '4.1'}, {'status': 'affected', 'version': '4.1.1'}, {'status': 'affected', 'version': '4.1.2'}, {'status': 'affected', 'version': '4.1.3'}, {'status': 'affected', 'version': '4.1.4'}, {'status': 'affected', 'version': '4.1.5'}, {'status': 'affected', 'version': '4.2'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:solaris:4.1.3:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'solaris', 'versions': [{'status': 'affected', 'version': '4.1.3'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:sun:sunos:4.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:4.1.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:4.1.3u1:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sun:sunos:5.4:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'sunos', 'versions': [{'status': 'affected', 'version': '4.1.1'}, {'status': 'affected', 'version': '4.1.2'}, {'status': 'affected', 'version': '4.1.3u1'}, {'status': 'affected', 'version': '5.0'}, {'status': 'affected', 'version': '5.1'}, {'status': 'affected', 'version': '5.2'}, {'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '5.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:13:12.881Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179', 'name': '00179', 'tags': ['vendor-advisory', 'x_refsource_SUN']}], 'descriptions': [{'lang': 'en', 'value': 'Local user gains root privileges via buffer overflow in rdist, via expstr() function.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179', 'name': '00179', 'refsource': 'SUN'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Local user gains root privileges via buffer overflow in rdist, via expstr() function.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0022', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0022', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:08:24.263Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0084
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-08-01 23:30:39.205373+03:00
['CWE-269']
2024-08-01 23:34:01.143000+03:00
59132a2893d56257022f79ac89b54c40159c19a7f81a692a579dddcd63cf8ee8
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/78', 'name': 'nfs-mknod(78)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.559Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0084', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:30:39.205373Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:sun:nfs:*:*:*:*:*:*:*:*'], 'vendor': 'sun', 'product': 'nfs', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '4.1.3', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-269', 'description': 'CWE-269 Improper Privilege Management'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:34:01.143Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/78', 'name': 'nfs-mknod(78)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/78', 'name': 'nfs-mknod(78)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0084', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0084', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:39:56.806Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-2320
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
none
yes
partial
2.0.3
2026-05-28 20:54:59.137685+03:00
['CWE-200']
2026-05-28 20:54:53.051000+03:00
eedb2ee740e4475f622cc5b51186cd74c15253732a89a3c3ff2be562879a220a
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/14959', 'name': 'weblogic-trace-xss(14959)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/867593', 'name': 'VU#867593', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://dev2dev.bea.com/pub/advisory/68', 'name': 'BEA04-48.01', 'tags': ['vendor-advisory', 'x_refsource_BEA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/9506', 'name': '9506', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/10726', 'name': '10726', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securitytracker.com/alerts/2004/Jan/1008866.html', 'name': '1008866', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.osvdb.org/3726', 'name': '3726', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:22:13.662Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2320', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:54:59.137685Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:54:53.051Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-01-27T00:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/14959', 'name': 'weblogic-trace-xss(14959)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.kb.cert.org/vuls/id/867593', 'name': 'VU#867593', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://dev2dev.bea.com/pub/advisory/68', 'name': 'BEA04-48.01', 'tags': ['vendor-advisory', 'x_refsource_BEA']}, {'url': 'http://www.securityfocus.com/bid/9506', 'name': '9506', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/10726', 'name': '10726', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securitytracker.com/alerts/2004/Jan/1008866.html', 'name': '1008866', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.osvdb.org/3726', 'name': '3726', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/14959', 'name': 'weblogic-trace-xss(14959)', 'refsource': 'XF'}, {'url': 'http://www.kb.cert.org/vuls/id/867593', 'name': 'VU#867593', 'refsource': 'CERT-VN'}, {'url': 'http://dev2dev.bea.com/pub/advisory/68', 'name': 'BEA04-48.01', 'refsource': 'BEA'}, {'url': 'http://www.securityfocus.com/bid/9506', 'name': '9506', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/10726', 'name': '10726', 'refsource': 'SECUNIA'}, {'url': 'http://www.securitytracker.com/alerts/2004/Jan/1008866.html', 'name': '1008866', 'refsource': 'SECTRACK'}, {'url': 'http://www.osvdb.org/3726', 'name': '3726', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2320', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2320', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:55:12.478Z', 'dateReserved': '2005-08-16T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-08-16T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-1999-1568
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2025-01-16 20:39:39.255679+03:00
['CWE-193']
2025-01-16 20:40:02.933000+03:00
fe5bfb67d4e83ad0e8ffbde8c56d2348137c9c7c54eeb6237d8a1a1024f10de6
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/12699', 'name': '19990223 Comments on NcFTPd "theoretical root compromise"', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1833', 'name': 'ncftpd-port-bo(1833)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=91981352617720&w=2', 'name': '19990223 NcFTPd remote buffer overflow', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T17:18:07.549Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-1568', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:39:39.255679Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-193', 'description': 'CWE-193 Off-by-one Error'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:40:02.933Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '1999-02-23T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/12699', 'name': '19990223 Comments on NcFTPd "theoretical root compromise"', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1833', 'name': 'ncftpd-port-bo(1833)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://marc.info/?l=bugtraq&m=91981352617720&w=2', 'name': '19990223 NcFTPd remote buffer overflow', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2003-03-21T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/12699', 'name': '19990223 Comments on NcFTPd "theoretical root compromise"', 'refsource': 'BUGTRAQ'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/1833', 'name': 'ncftpd-port-bo(1833)', 'refsource': 'XF'}, {'url': 'http://marc.info/?l=bugtraq&m=91981352617720&w=2', 'name': '19990223 NcFTPd remote buffer overflow', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-1568', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-1568', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:40:42.694Z', 'dateReserved': '2001-08-31T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-01T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0036
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-08-01 22:38:13.056705+03:00
['CWE-434']
2024-08-01 22:44:45.984000+03:00
c3d04f2ab9106efbe19d9a5185a968e46eea2a1b308a014397fc9b8c5a1c8f13
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/990', 'name': '990', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.ciac.org/ciac/bulletins/h-106.shtml', 'name': 'H-106', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX', 'name': '19970508-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/557', 'name': 'sgi-lockout(557)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.712Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0036', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:38:13.056705Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:5.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:xfs:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.4:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.0'}, {'status': 'affected', 'version': '5.0.1'}, {'status': 'affected', 'version': '5.1'}, {'status': 'affected', 'version': '5.1.1'}, {'status': 'affected', 'version': '5.2'}, {'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '6.0'}, {'status': 'affected', 'version': '6.0.1'}, {'status': 'affected', 'version': '6.1'}, {'status': 'affected', 'version': '6.2'}, {'status': 'affected', 'version': '6.3'}, {'status': 'affected', 'version': '6.4'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-434', 'description': 'CWE-434 Unrestricted Upload of File with Dangerous Type'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:44:45.984Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/990', 'name': '990', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.ciac.org/ciac/bulletins/h-106.shtml', 'name': 'H-106', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX', 'name': '19970508-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/557', 'name': 'sgi-lockout(557)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/990', 'name': '990', 'refsource': 'OSVDB'}, {'url': 'http://www.ciac.org/ciac/bulletins/h-106.shtml', 'name': 'H-106', 'refsource': 'CIAC'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX', 'name': '19970508-02-PX', 'refsource': 'SGI'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/557', 'name': 'sgi-lockout(557)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0036', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0036', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:07:28.583Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-0369
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
none
yes
partial
2.0.3
2024-02-09 22:37:41.057871+03:00
['CWE-129']
2025-01-16 20:49:02.640000+03:00
fbb81ca75a59cd1b2276932e5bdd8a8cbd2728aa99c6024723844ce84af601af
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=110811699206052&w=2', 'name': '20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:13:53.455Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-0369', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-09T19:37:41.057871Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-129', 'description': 'CWE-129 Improper Validation of Array Index'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:49:02.640Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-02-10T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=110811699206052&w=2', 'name': '20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T13:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=110811699206052&w=2', 'name': '20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-0369', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-0369', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:49:34.444Z', 'dateReserved': '2005-02-11T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-02-11T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-1464
5.90
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
active
no
partial
2.0.3
2025-02-07 17:29:07.632839+03:00
['CWE-400']
2025-02-07 17:28:43.653000+03:00
9914dc0dd395e54c17e173072ab2a2b221153098c490c1b1f3ab2009d4f1e32a
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17131', 'name': 'cisco-ios-telnet-dos(17131)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1011079', 'name': '1011079', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/384230', 'name': 'VU#384230', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://secunia.com/advisories/12395/', 'name': '12395', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml', 'name': '20040827 Cisco Telnet Denial of Service Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/11060', 'name': '11060', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:53:23.947Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-1464', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:29:07.632839Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2023-05-19', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-1464'}}}], 'timeline': [{'lang': 'en', 'time': '2023-05-19T00:00:00.000Z', 'value': 'CVE-2004-1464 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-1464', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:28:43.653Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-08-27T00:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17131', 'name': 'cisco-ios-telnet-dos(17131)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://securitytracker.com/id?1011079', 'name': '1011079', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.kb.cert.org/vuls/id/384230', 'name': 'VU#384230', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://secunia.com/advisories/12395/', 'name': '12395', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml', 'name': '20040827 Cisco Telnet Denial of Service Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://www.securityfocus.com/bid/11060', 'name': '11060', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/17131', 'name': 'cisco-ios-telnet-dos(17131)', 'refsource': 'XF'}, {'url': 'http://securitytracker.com/id?1011079', 'name': '1011079', 'refsource': 'SECTRACK'}, {'url': 'http://www.kb.cert.org/vuls/id/384230', 'name': 'VU#384230', 'refsource': 'CERT-VN'}, {'url': 'http://secunia.com/advisories/12395/', 'name': '12395', 'refsource': 'SECUNIA'}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml', 'name': '20040827 Cisco Telnet Denial of Service Vulnerability', 'refsource': 'CISCO'}, {'url': 'http://www.securityfocus.com/bid/11060', 'name': '11060', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-1464', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-1464', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.162Z', 'dateReserved': '2005-02-13T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-02-13T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2003-20001
5.60
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
none
no
partial
2.0.3
2025-04-04 23:20:21.648275+03:00
['CWE-200']
2025-04-04 23:22:04.492000+03:00
d142801479bb35c5484b8a8a6c9152ac547f377dea3a13e8f3035bd84804536d
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.6, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2003-20001', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-04T20:20:21.648275Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-04T20:22:04.492Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://packetstorm.news/files/id/31445'}, {'url': 'http://olografix.org/acme/mitel.txt'}, {'url': 'https://rb.gy/1smt22'}, {'url': 'https://www.exploit-db.com/exploits/49176'}], 'descriptions': [{'lang': 'en', 'value': 'An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2025-04-01T21:01:21.094Z'}}}, 'cveMetadata': {'cveId': 'CVE-2003-20001', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-04T20:22:13.607Z', 'dateReserved': '2025-03-28T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2025-04-01T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-1796
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-02-09 20:57:39.682936+03:00
['CWE-347']
2025-01-16 22:23:32.490000+03:00
57f0e0f7b730a2b9e2d7062b85fc785662562b227264ef8e9fdea67c3852bb34
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/5334', 'name': '5334', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://online.securityfocus.com/advisories/4317', 'name': 'HPSBUX0207-203', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/9695.php', 'name': 'hp-chaivm-add-services(9695)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/284648', 'name': '20020227 Phenoelit Advisory #0815 +--', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:34:56.348Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1796', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-09T17:57:39.682936Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-347', 'description': 'CWE-347 Improper Verification of Cryptographic Signature'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:23:32.490Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/5334', 'name': '5334', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://online.securityfocus.com/advisories/4317', 'name': 'HPSBUX0207-203', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.iss.net/security_center/static/9695.php', 'name': 'hp-chaivm-add-services(9695)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/archive/1/284648', 'name': '20020227 Phenoelit Advisory #0815 +--', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-06-28T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'name': 'http://www.phenoelit.de/stuff/HP_Chai.txt', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/5334', 'name': '5334', 'refsource': 'BID'}, {'url': 'http://online.securityfocus.com/advisories/4317', 'name': 'HPSBUX0207-203', 'refsource': 'HP'}, {'url': 'http://www.iss.net/security_center/static/9695.php', 'name': 'hp-chaivm-add-services(9695)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/archive/1/284648', 'name': '20020227 Phenoelit Advisory #0815 +--', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1796', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1796', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:24:39.019Z', 'dateReserved': '2005-06-28T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-28T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0517
5.90
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
no
partial
2.0.3
2026-05-28 20:34:44.093859+03:00
['CWE-200']
2026-05-28 20:34:40.117000+03:00
134669fa31e4dd0ceff0cf77679ffdc7b5bc708e21b791a4cb783f577f7f2c2e
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-244'}, {'url': 'https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-244/'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2025-03-17T15:03:23.650Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0517', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T17:34:44.093859Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T17:34:40.117Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'An SNMP community name is the default (e.g. public), null, or missing.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T07:45:39.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'An SNMP community name is the default (e.g. public), null, or missing.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0517', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0517', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T17:34:53.144Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2000-02-04T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-2005-10004
poc
no
total
2.0.3
2025-09-02 23:43:58.409178+03:00
2025-09-02 23:44:05.677000+03:00
e8e0887ee0f0aa047094c6f854b27a65c81b1b94b063300bedb968c66cca8f52
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-10004', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'poc'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-09-02T20:43:58.409178Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-09-02T20:44:05.677Z'}}], 'cna': {'title': 'Cacti graph_view.php RCE via graph_start Parameter Injection', 'source': {'discovery': 'UNKNOWN'}, 'credits': [{'lang': 'en', 'type': 'finder', 'value': 'David Maciejak'}], 'impacts': [{'capecId': 'CAPEC-88', 'descriptions': [{'lang': 'en', 'value': 'CAPEC-88 OS Command Injection'}]}], 'metrics': [{'format': 'CVSS', 'cvssV4_0': {'Safety': 'NOT_DEFINED', 'version': '4.0', 'Recovery': 'NOT_DEFINED', 'baseScore': 8.7, 'Automatable': 'NOT_DEFINED', 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'valueDensity': 'NOT_DEFINED', 'vectorString': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'providerUrgency': 'NOT_DEFINED', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'attackRequirements': 'NONE', 'privilegesRequired': 'LOW', 'subIntegrityImpact': 'NONE', 'vulnIntegrityImpact': 'HIGH', 'subAvailabilityImpact': 'NONE', 'vulnAvailabilityImpact': 'HIGH', 'subConfidentialityImpact': 'NONE', 'vulnConfidentialityImpact': 'HIGH', 'vulnerabilityResponseEffort': 'NOT_DEFINED'}, 'scenarios': [{'lang': 'en', 'value': 'GENERAL'}]}], 'affected': [{'vendor': 'Raxnet/Ian Berry', 'modules': ['graph_view.php (web interface script responsible for rendering graphs)'], 'product': 'Cacti', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '0.8.6-d', 'versionType': 'semver'}], 'defaultStatus': 'unaffected'}], 'datePublic': '2005-01-15T00:00:00.000Z', 'references': [{'url': 'https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/cacti_graphimage_exec.rb', 'tags': ['exploit']}, {'url': 'https://www.exploit-db.com/exploits/9911', 'tags': ['exploit']}, {'url': 'https://www.exploit-db.com/exploits/16881', 'tags': ['exploit']}, {'url': 'https://www.cacti.net/info/downloads', 'tags': ['product']}, {'url': 'https://web.archive.org/web/20050305034552/http://www.cacti.net/cactid_download.php', 'tags': ['product', 'patch']}, {'url': 'https://www.vulncheck.com/advisories/cacti-graph-view-rce', 'tags': ['third-party-advisory']}], 'x_generator': {'engine': 'Vulnogram 0.2.0'}, 'descriptions': [{'lang': 'en', 'value': 'Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.', 'supportingMedia': [{'type': 'text/html', 'value': 'Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.', 'base64': False}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], 'providerMetadata': {'orgId': '83251b91-4cc7-4094-a5c7-464a1b83ea10', 'shortName': 'VulnCheck', 'dateUpdated': '2026-05-15T11:13:09.188Z'}}}, 'cveMetadata': {'cveId': 'CVE-2005-10004', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-15T11:13:09.188Z', 'dateReserved': '2025-08-28T18:08:00.944Z', 'assignerOrgId': '83251b91-4cc7-4094-a5c7-464a1b83ea10', 'datePublished': '2025-08-30T13:45:16.222Z', 'assignerShortName': 'VulnCheck'}, 'dataVersion': '5.2'}
CVE-2004-2257
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
none
yes
partial
2.0.3
2024-01-30 19:36:54.394607+03:00
['CWE-425']
2025-01-16 22:34:51.596000+03:00
b911d89d6a8625450d5c6c554403eec1374101bf2ab6da24d96ce91bfc07cc3b
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/8240', 'name': '8240', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1010795', 'name': '1010795', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://secunia.com/advisories/12085', 'name': '12085', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16814', 'name': 'phpmyfaq-authentication-bypass(16814)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/10813', 'name': '10813', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:22:13.486Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2257', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-30T16:36:54.394607Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-425', 'description': "CWE-425 Direct Request ('Forced Browsing')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:34:51.596Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-07-27T00:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/8240', 'name': '8240', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://securitytracker.com/id?1010795', 'name': '1010795', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://secunia.com/advisories/12085', 'name': '12085', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16814', 'name': 'phpmyfaq-authentication-bypass(16814)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/bid/10813', 'name': '10813', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/8240', 'name': '8240', 'refsource': 'OSVDB'}, {'url': 'http://securitytracker.com/id?1010795', 'name': '1010795', 'refsource': 'SECTRACK'}, {'url': 'http://secunia.com/advisories/12085', 'name': '12085', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16814', 'name': 'phpmyfaq-authentication-bypass(16814)', 'refsource': 'XF'}, {'url': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'name': 'http://www.phpmyfaq.de/advisory_2004-07-27.php', 'refsource': 'CONFIRM'}, {'url': 'http://www.securityfocus.com/bid/10813', 'name': '10813', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-2257', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-2257', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:34:58.763Z', 'dateReserved': '2005-07-17T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-17T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-0051
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2025-01-16 20:12:27.298249+03:00
['CWE-667']
2025-01-16 20:11:29.033000+03:00
546ccdf134ac71bd0ff8869894de8c0c9a578aa384a8858ba63acbafed85962e
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://online.securityfocus.com/archive/1/244329', 'name': '20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A38', 'name': 'oval:org.mitre.oval:def:38', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-016', 'name': 'MS02-016', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/4438', 'name': '4438', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:35:17.461Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0051', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-16T17:12:27.298249Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-667', 'description': 'CWE-667 Improper Locking'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:11:29.033Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-04-04T00:00:00.000Z', 'references': [{'url': 'http://online.securityfocus.com/archive/1/244329', 'name': '20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A38', 'name': 'oval:org.mitre.oval:def:38', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-016', 'name': 'MS02-016', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.securityfocus.com/bid/4438', 'name': '4438', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2002-06-16T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://online.securityfocus.com/archive/1/244329', 'name': '20011205 SECURITY.NNOV: file locking and security (group policy DoS on Windows 2000 domain)', 'refsource': 'BUGTRAQ'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A38', 'name': 'oval:org.mitre.oval:def:38', 'refsource': 'OVAL'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-016', 'name': 'MS02-016', 'refsource': 'MS'}, {'url': 'http://www.securityfocus.com/bid/4438', 'name': '4438', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0051', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0051', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:12:31.750Z', 'dateReserved': '2002-02-02T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-06-25T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-20002
none
no
partial
2.0.3
2025-01-07 00:08:18.044511+03:00
2025-01-07 00:08:24.787000+03:00
03c08c9743350f89247ef89db0893735ec1cbea6486bccb07b81af191066d9d1
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-20002', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-06T21:08:18.044511Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-06T21:08:24.787Z'}}], 'cna': {'metrics': [{'cvssV3_1': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}}], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://metacpan.org/release/MNAGUIB/EasyTCP-0.26/changes'}, {'url': 'https://github.com/briandfoy/cpan-security-advisory/issues/184'}, {'url': 'https://metacpan.org/release/MNAGUIB/EasyTCP-0.15/view/EasyTCP.pm'}], 'x_generator': {'engine': 'enrichogram 0.0.1'}, 'descriptions': [{'lang': 'en', 'value': "The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-338', 'description': 'CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2025-01-02T05:00:27.855Z'}}}, 'cveMetadata': {'cveId': 'CVE-2002-20002', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-06T21:08:29.156Z', 'dateReserved': '2025-01-02T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2025-01-02T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0059
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
partial
2.0.3
2024-08-01 23:34:06.831485+03:00
['CWE-200']
2024-08-01 23:35:42.893000+03:00
bdcde216710505074c597969643b5a56ec17fde51bbe0355cde190340fc2e259
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/164', 'name': '164', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/353', 'name': '353', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/325', 'name': 'irix-fam(325)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.256Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0059', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:34:06.831485Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.3:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '5.3'}, {'status': 'affected', 'version': '6.1'}, {'status': 'affected', 'version': '6.2'}, {'status': 'affected', 'version': '6.3'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:35:42.893Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/164', 'name': '164', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/353', 'name': '353', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/325', 'name': 'irix-fam(325)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'IRIX fam service allows an attacker to obtain a list of all files on the server.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/164', 'name': '164', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/353', 'name': '353', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/325', 'name': 'irix-fam(325)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'IRIX fam service allows an attacker to obtain a list of all files on the server.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0059', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0059', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:35:57.570Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2003-1567
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
none
yes
partial
2.0.3
2026-05-28 21:23:10.554802+03:00
['CWE-200']
['https://www.aqtronix.com/Advisories/AQ-2003-02.txt']
2026-05-28 21:23:03.291000+03:00
a7034f6b512f1e06e71f68491e6d86539fb1c33b4e15b13b7e51c29f00c31982
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html', 'name': '20031227 AQ-2003-02: Microsoft IIS Logging Failure', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/288308', 'name': 'VU#288308', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/5648', 'name': '5648', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:35:17.592Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2003-1567', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-28T18:23:10.554802Z'}}}], 'references': [{'url': 'https://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'tags': ['exploit']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-28T18:23:03.291Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html', 'name': '20031227 AQ-2003-02: Microsoft IIS Logging Failure', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ']}, {'url': 'http://www.kb.cert.org/vuls/id/288308', 'name': 'VU#288308', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/5648', 'name': '5648', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2009-01-15T00:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html', 'name': '20031227 AQ-2003-02: Microsoft IIS Logging Failure', 'refsource': 'NTBUGTRAQ'}, {'url': 'http://www.kb.cert.org/vuls/id/288308', 'name': 'VU#288308', 'refsource': 'CERT-VN'}, {'url': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'name': 'http://www.aqtronix.com/Advisories/AQ-2003-02.txt', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/5648', 'name': '5648', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2003-1567', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2003-1567', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-28T18:23:16.713Z', 'dateReserved': '2009-01-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2009-01-15T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-1999-1413
none
no
partial
2.0.3
2024-08-01 22:40:04.144434+03:00
2024-08-01 22:40:10.351000+03:00
40c991b92da1366aa770004690214c5163909b349e9d7a67ede933f869770edc
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=87602167419549&w=2', 'name': '19960803 Exploiting Zolaris 2.4 ?? :)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/296', 'name': '296', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T17:11:03.182Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-1413', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:40:04.144434Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:40:10.351Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '1996-08-03T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=87602167419549&w=2', 'name': '19960803 Exploiting Zolaris 2.4 ?? :)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/296', 'name': '296', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T13:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=87602167419549&w=2', 'name': '19960803 Exploiting Zolaris 2.4 ?? :)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/296', 'name': '296', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-1413', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-1413', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T19:40:14.542Z', 'dateReserved': '2001-08-31T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-09-12T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0159
3.50
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
none
no
partial
2.0.3
2025-08-27 21:38:07.688027+03:00
['CWE-400']
2025-08-27 20:45:45.182000+03:00
71d084ad09c6526ce559de969bc896ff19a263eb1a29d5481ef1f6d7e746ac8c
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.802Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.5, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0159', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-08-27T18:38:07.688027Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-08-27T17:45:45.182Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:49:36.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0159', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0159', 'state': 'PUBLISHED', 'dateUpdated': '2025-08-27T18:38:54.613Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-10003
none
no
partial
2.0.3
2024-10-17 19:12:56.245378+03:00
2024-10-17 19:13:02.642000+03:00
21a1f135b2dfd00a8fcfef79fa57f79402e86d0e375bfddbf273c704a8b8ecca
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-10003', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-10-17T16:12:56.245378Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-17T16:13:02.642Z'}}], 'cna': {'tags': ['unsupported-when-assigned'], 'title': 'mikexstudios Xcomic os command injection', 'metrics': [{'cvssV4_0': {'version': '4.0', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}}, {'cvssV3_1': {'version': '3.1', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}}, {'cvssV3_0': {'version': '3.0', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}}, {'cvssV2_0': {'version': '2.0', 'baseScore': 5.1, 'vectorString': 'AV:N/AC:H/Au:N/C:P/I:P/A:P'}}], 'affected': [{'vendor': 'mikexstudios', 'product': 'Xcomic', 'versions': [{'status': 'affected', 'version': '0.8.0'}, {'status': 'affected', 'version': '0.8.1'}, {'status': 'affected', 'version': '0.8.2'}]}], 'timeline': [{'lang': 'en', 'time': '2005-07-20T00:00:00.000Z', 'value': 'Advisory disclosed'}, {'lang': 'en', 'time': '2005-07-22T00:00:00.000Z', 'value': 'Countermeasure disclosed'}, {'lang': 'en', 'time': '2024-10-15T02:00:00.000Z', 'value': 'VulDB entry created'}, {'lang': 'en', 'time': '2024-10-15T11:55:54.000Z', 'value': 'VulDB entry last update'}], 'references': [{'url': 'https://vuldb.com/?id.280359', 'name': 'VDB-280359 | mikexstudios Xcomic os command injection', 'tags': ['vdb-entry', 'technical-description']}, {'url': 'https://vuldb.com/?ctiid.280359', 'name': 'VDB-280359 | CTI Indicators (IOB, IOC, TTP, IOA)', 'tags': ['signature', 'permissions-required']}, {'url': 'http://xcomic.mikexstudios.com/forum/viewtopic.php?id=130', 'tags': ['broken-link', 'exploit']}, {'url': 'https://github.com/mikexstudios/xcomic/commit/6ed8e3cc336e29f09c7e791863d0559939da98bf', 'tags': ['patch']}, {'url': 'https://github.com/mikexstudios/xcomic/releases/tag/v0.8.3', 'tags': ['patch']}, {'url': 'https://web.archive.org/web/20071218144304/http://xcomic.mikexstudios.com/forum/viewtopic.php?id=130', 'tags': ['related']}], 'descriptions': [{'lang': 'en', 'value': 'A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.3 is able to address this issue. The patch is named 6ed8e3cc336e29f09c7e791863d0559939da98bf. It is recommended to upgrade the affected component.'}, {'lang': 'de', 'value': 'Es wurde eine Schwachstelle in mikexstudios Xcomic bis 0.8.2 entdeckt. Sie wurde als kritisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf. Mit der Manipulation des Arguments cmd mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Die Komplexität eines Angriffs ist eher hoch. Sie ist schwierig auszunutzen. Der Exploit steht zur öffentlichen Verfügung. Ein Aktualisieren auf die Version 0.8.3 vermag dieses Problem zu lösen. Der Patch wird als 6ed8e3cc336e29f09c7e791863d0559939da98bf bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': 'OS Command Injection'}]}], 'providerMetadata': {'orgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'shortName': 'VulDB', 'dateUpdated': '2024-10-17T14:00:16.571Z'}}}, 'cveMetadata': {'cveId': 'CVE-2005-10003', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-17T16:13:06.608Z', 'dateReserved': '2024-10-15T09:49:35.446Z', 'assignerOrgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'datePublished': '2024-10-17T14:00:16.571Z', 'assignerShortName': 'VulDB'}, 'dataVersion': '5.1'}
CVE-2004-2154
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-07-16 17:59:33.852643+03:00
['CWE-178']
2024-07-16 18:00:32.347000+03:00
726192eb7b80a355ea5495b02b4400205e84c8712b121f74db67c782dc010a20
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2005_18_sr.html', 'name': 'SUSE-SR:2005:018', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.cups.org/str.php?L700', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-571.html', 'name': 'RHSA-2005:571', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274', 'name': 'FLSA:163274', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-185-1', 'name': 'USN-185-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9940', 'name': 'oval:org.mitre.oval:def:9940', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:15:01.684Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-2154', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-07-16T14:59:33.852643Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:apple:cups:-:*:*:*:*:*:*:*'], 'vendor': 'apple', 'product': 'cups', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '1.1.21', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:canonical:ubuntu_linux:4.10:*:*:*:*:*:*:*'], 'vendor': 'canonical', 'product': 'ubuntu_linux', 'versions': [{'status': 'affected', 'version': '4.10'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-178', 'description': 'CWE-178 Improper Handling of Case Sensitivity'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-07-16T15:00:32.347Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-05-13T00:00:00.000Z', 'references': [{'url': 'http://www.novell.com/linux/security/advisories/2005_18_sr.html', 'name': 'SUSE-SR:2005:018', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.cups.org/str.php?L700', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-571.html', 'name': 'RHSA-2005:571', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274', 'name': 'FLSA:163274', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.ubuntu.com/usn/usn-185-1', 'name': 'USN-185-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9940', 'name': 'oval:org.mitre.oval:def:9940', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2017-10-10T00:57:01.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2004-2154', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-08T01:15:01.684Z', 'dateReserved': '2005-07-05T00:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2005-07-05T04:00:00.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'}
CVE-2001-1125
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-02-08 20:21:18.892262+03:00
['CWE-494']
2025-01-16 20:03:58.429000+03:00
3fc20a10f8baf35ecdb04e49aeed86c6279ac39269e172acfa1f86fe01349d86
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/218717', 'name': '20011005 Symantec LiveUpdate attacks', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/3403', 'name': '3403', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7235', 'name': 'liveupdate-host-verification(7235)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:44:07.831Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-1125', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-08T17:21:18.892262Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-494', 'description': 'CWE-494 Download of Code Without Integrity Check'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:03:58.429Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-10-05T04:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/218717', 'name': '20011005 Symantec LiveUpdate attacks', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/3403', 'name': '3403', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7235', 'name': 'liveupdate-host-verification(7235)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-12-19T02:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/218717', 'name': '20011005 Symantec LiveUpdate attacks', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/3403', 'name': '3403', 'refsource': 'BID'}, {'url': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'name': 'http://www.sarc.com/avcenter/security/Content/2001.10.05.html', 'refsource': 'CONFIRM'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/7235', 'name': 'liveupdate-host-verification(7235)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-1125', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-1125', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:04:41.599Z', 'dateReserved': '2002-03-15T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2002-03-15T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2001-0827
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2025-04-23 16:47:02.079015+03:00
['CWE-400']
2025-04-23 18:37:32.655000+03:00
115bb2704b929a6028a9a4684df64dab522222de729249dfaf358a3e63ca229e
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html', 'name': '20010704 CesarFTPd, Cerberus FTPd', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/2976', 'name': '2976', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T04:37:06.984Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0827', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-23T13:47:02.079015Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-23T15:37:32.655Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-07-04T00:00:00.000Z', 'references': [{'url': 'http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html', 'name': '20010704 CesarFTPd, Cerberus FTPd', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/2976', 'name': '2976', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2001-11-28T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html', 'name': '20010704 CesarFTPd, Cerberus FTPd', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/2976', 'name': '2976', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0827', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0827', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-23T15:37:38.404Z', 'dateReserved': '2001-11-22T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-11-22T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-0210
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
active
no
total
2.0.3
2025-02-07 17:32:41.753543+03:00
['CWE-120']
2025-02-07 17:33:00.465000+03:00
0338c0f3a54dc3d8994f35b0b21212d45aa56c89330f225030bc423e7fb87c54
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.us-cert.gov/cas/techalerts/TA04-196A.html', 'name': 'TA04-196A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/647436', 'name': 'VU#647436', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166', 'name': 'oval:org.mitre.oval:def:2166', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020', 'name': 'MS04-020', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847', 'name': 'oval:org.mitre.oval:def:2847', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16590', 'name': 'win-posix-bo(16590)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:10:03.856Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0210', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:32:41.753543Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-03-03', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210'}}}], 'timeline': [{'lang': 'en', 'time': '2022-03-03T00:00:00.000Z', 'value': 'CVE-2004-0210 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-0210', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-120', 'description': "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:33:00.465Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-07-13T00:00:00.000Z', 'references': [{'url': 'http://www.us-cert.gov/cas/techalerts/TA04-196A.html', 'name': 'TA04-196A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.kb.cert.org/vuls/id/647436', 'name': 'VU#647436', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166', 'name': 'oval:org.mitre.oval:def:2166', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020', 'name': 'MS04-020', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847', 'name': 'oval:org.mitre.oval:def:2847', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16590', 'name': 'win-posix-bo(16590)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-12T19:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.us-cert.gov/cas/techalerts/TA04-196A.html', 'name': 'TA04-196A', 'refsource': 'CERT'}, {'url': 'http://www.kb.cert.org/vuls/id/647436', 'name': 'VU#647436', 'refsource': 'CERT-VN'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2166', 'name': 'oval:org.mitre.oval:def:2166', 'refsource': 'OVAL'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-020', 'name': 'MS04-020', 'refsource': 'MS'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2847', 'name': 'oval:org.mitre.oval:def:2847', 'refsource': 'OVAL'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/16590', 'name': 'win-posix-bo(16590)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0210', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0210', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.314Z', 'dateReserved': '2004-03-11T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0013
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
partial
2.0.3
2024-08-01 21:59:12.970313+03:00
['CWE-522']
2024-08-01 22:02:37.469000+03:00
ef8575e177eda91d123be885ec6d465ce8a8d851f08dbe79d9cff8c68ca4cc10
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.463Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0013', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T18:59:12.970313Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*'], 'vendor': 'ssh', 'product': 'ssh', 'versions': [{'status': 'affected', 'version': '1.2.0'}, {'status': 'affected', 'version': '1.2.1'}, {'status': 'affected', 'version': '1.2.2'}, {'status': 'affected', 'version': '1.2.3'}, {'status': 'affected', 'version': '1.2.4'}, {'status': 'affected', 'version': '1.2.5'}, {'status': 'affected', 'version': '1.2.6'}, {'status': 'affected', 'version': '1.2.7'}, {'status': 'affected', 'version': '1.2.8'}, {'status': 'affected', 'version': '1.2.9'}, {'status': 'affected', 'version': '1.2.10'}, {'status': 'affected', 'version': '1.2.11'}, {'status': 'affected', 'version': '1.2.12'}, {'status': 'affected', 'version': '1.2.13'}, {'status': 'affected', 'version': '1.2.14'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-522', 'description': 'CWE-522 Insufficiently Protected Credentials'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:02:37.469Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:24:59.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0013', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0013', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0013', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T19:02:44.132Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0039
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
partial
2.0.3
2024-09-04 18:36:17.863572+03:00
['CWE-77']
2024-09-04 18:21:04.306000+03:00
554f2a8182ae670c1caee150cbda20ec7cd7b2f5230f70c230e44a1343332294
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX', 'name': '19970501-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/333', 'name': 'http-sgi-webdist(333)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.cert.org/advisories/CA-1997-12.html', 'name': 'CA-1997-12', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/374', 'name': '374', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.osvdb.org/235', 'name': '235', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.773Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0039', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-09-04T15:36:17.863572Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:-:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '0'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-77', 'description': "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-09-04T15:21:04.306Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX', 'name': '19970501-02-PX', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/333', 'name': 'http-sgi-webdist(333)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.cert.org/advisories/CA-1997-12.html', 'name': 'CA-1997-12', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.securityfocus.com/bid/374', 'name': '374', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.osvdb.org/235', 'name': '235', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX', 'name': '19970501-02-PX', 'refsource': 'SGI'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/333', 'name': 'http-sgi-webdist(333)', 'refsource': 'XF'}, {'url': 'http://www.cert.org/advisories/CA-1997-12.html', 'name': 'CA-1997-12', 'refsource': 'CERT'}, {'url': 'http://www.securityfocus.com/bid/374', 'name': '374', 'refsource': 'BID'}, {'url': 'http://www.osvdb.org/235', 'name': '235', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0039', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0039', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-12T14:37:05.701Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2003-0063
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
partial
2.0.3
2024-07-24 20:38:21.119752+03:00
2024-07-24 20:39:25.055000+03:00
a66a1e61c9f2455f46706b2dedcec31091149163e4f9506f00192de16e4afcc6
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.debian.org/security/2003/dsa-380', 'name': 'DSA-380', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-067.html', 'name': 'RHSA-2003:067', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-066.html', 'name': 'RHSA-2003:066', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=104612710031920&w=2', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-064.html', 'name': 'RHSA-2003:064', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-065.html', 'name': 'RHSA-2003:065', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/6940', 'name': '6940', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/11414.php', 'name': 'terminal-emulator-window-title(11414)', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.openwall.com/lists/oss-security/2024/06/15/1', 'name': '[oss-security] 20240615 iTerm2 3.5.x title reporting bug', 'tags': ['mailing-list', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:43:35.241Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2003-0063', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-07-24T17:38:21.119752Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:xfree86:xfree86:*:*:*:*:*:*:*:*'], 'vendor': 'xfree86', 'product': 'xfree86', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '4.2.0'}], 'defaultStatus': 'unknown'}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-07-24T17:39:25.055Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2003-02-24T05:00:00.000Z', 'references': [{'url': 'http://www.debian.org/security/2003/dsa-380', 'name': 'DSA-380', 'tags': ['vendor-advisory']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-067.html', 'name': 'RHSA-2003:067', 'tags': ['vendor-advisory']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-066.html', 'name': 'RHSA-2003:066', 'tags': ['vendor-advisory']}, {'url': 'http://marc.info/?l=bugtraq&m=104612710031920&w=2', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-064.html', 'name': 'RHSA-2003:064', 'tags': ['vendor-advisory']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2003-065.html', 'name': 'RHSA-2003:065', 'tags': ['vendor-advisory']}, {'url': 'http://www.securityfocus.com/bid/6940', 'name': '6940', 'tags': ['vdb-entry']}, {'url': 'http://www.iss.net/security_center/static/11414.php', 'name': 'terminal-emulator-window-title(11414)', 'tags': ['vdb-entry']}, {'url': 'http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html', 'name': '20030224 Terminal Emulator Security Issues', 'tags': ['mailing-list']}, {'url': 'http://www.openwall.com/lists/oss-security/2024/06/15/1', 'name': '[oss-security] 20240615 iTerm2 3.5.x title reporting bug', 'tags': ['mailing-list']}], 'descriptions': [{'lang': 'en', 'value': "The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2024-06-15T14:05:53.568Z'}}}, 'cveMetadata': {'cveId': 'CVE-2003-0063', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:05:49.769Z', 'dateReserved': '2003-02-04T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-01T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-1372
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2024-01-25 18:24:01.752587+03:00
['CWE-252']
2025-01-16 20:42:04.551000+03:00
f1eaff9c92017ddc38e1804ec8cc8feea966abbb6f0a18fe2674a50e22369028
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_VULNWATCH', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702', 'name': 'CLSA-2003:702', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'http://www.debian.org/security/2003/dsa-232', 'name': 'DSA-232', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2003_002_cups.html', 'name': 'SuSE-SA:2003:002', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.idefense.com/advisory/12.19.02.txt', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-295.html', 'name': 'RHSA-2002:295', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=104032149026670&w=2', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001', 'name': 'MDKSA-2003:001', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/6440', 'name': '6440', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/10912', 'name': 'cups-file-descriptor-dos(10912)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:19:28.771Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-1372', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-25T15:24:01.752587Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-252', 'description': 'CWE-252 Unchecked Return Value'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:42:04.551Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-12-19T05:00:00.000Z', 'references': [{'url': 'http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_VULNWATCH']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702', 'name': 'CLSA-2003:702', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'http://www.debian.org/security/2003/dsa-232', 'name': 'DSA-232', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.novell.com/linux/security/advisories/2003_002_cups.html', 'name': 'SuSE-SA:2003:002', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.idefense.com/advisory/12.19.02.txt', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-295.html', 'name': 'RHSA-2002:295', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://marc.info/?l=bugtraq&m=104032149026670&w=2', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001', 'name': 'MDKSA-2003:001', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://www.securityfocus.com/bid/6440', 'name': '6440', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/10912', 'name': 'cups-file-descriptor-dos(10912)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2007-12-20T05:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0117.html', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'refsource': 'VULNWATCH'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000702', 'name': 'CLSA-2003:702', 'refsource': 'CONECTIVA'}, {'url': 'http://www.debian.org/security/2003/dsa-232', 'name': 'DSA-232', 'refsource': 'DEBIAN'}, {'url': 'http://www.novell.com/linux/security/advisories/2003_002_cups.html', 'name': 'SuSE-SA:2003:002', 'refsource': 'SUSE'}, {'url': 'http://www.idefense.com/advisory/12.19.02.txt', 'name': 'http://www.idefense.com/advisory/12.19.02.txt', 'refsource': 'MISC'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2002-295.html', 'name': 'RHSA-2002:295', 'refsource': 'REDHAT'}, {'url': 'http://marc.info/?l=bugtraq&m=104032149026670&w=2', 'name': '20021219 iDEFENSE Security Advisory 12.19.02: Multiple Security Vulnerabilities in Common Unix Printing System (CUPS)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001', 'name': 'MDKSA-2003:001', 'refsource': 'MANDRAKE'}, {'url': 'http://www.securityfocus.com/bid/6440', 'name': '6440', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/10912', 'name': 'cups-file-descriptor-dos(10912)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-1372', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-1372', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:42:09.355Z', 'dateReserved': '2002-12-16T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-09-01T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-3274
none
no
partial
2.0.3
2024-04-02 21:26:04.388396+03:00
2024-10-15 17:14:56.457000+03:00
ade63bd58c2065b863b04acf4a765d9620d4b2f38b11da3f28c92aaf4a51509b
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:235', 'name': 'MDKSA-2005:235', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18684', 'name': '18684', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18977', 'name': '18977', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:220', 'name': 'MDKSA-2005:220', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044', 'name': 'MDKSA-2006:044', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/15528', 'name': '15528', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/427981/100/0/threaded', 'name': 'FLSA:157459-4', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/219-1/', 'name': 'USN-219-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0190.html', 'name': 'RHSA-2006:0190', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:218', 'name': 'MDKSA-2005:218', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17826', 'name': '17826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://lkml.org/lkml/2005/6/23/249', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://lkml.org/lkml/2005/6/24/173', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723', 'name': 'oval:org.mitre.oval:def:11723', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-663.html', 'name': 'RHSA-2005:663', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:219', 'name': 'MDKSA-2005:219', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:10:07.282Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3274', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-02T18:26:04.388396Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-15T14:14:56.457Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-07-26T00:00:00.000Z', 'references': [{'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:235', 'name': 'MDKSA-2005:235', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA']}, {'url': 'http://secunia.com/advisories/18684', 'name': '18684', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/18977', 'name': '18977', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:220', 'name': 'MDKSA-2005:220', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044', 'name': 'MDKSA-2006:044', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA']}, {'url': 'http://www.securityfocus.com/bid/15528', 'name': '15528', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.securityfocus.com/archive/1/427981/100/0/threaded', 'name': 'FLSA:157459-4', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://usn.ubuntu.com/219-1/', 'name': 'USN-219-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0190.html', 'name': 'RHSA-2006:0190', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:218', 'name': 'MDKSA-2005:218', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'http://secunia.com/advisories/17826', 'name': '17826', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://lkml.org/lkml/2005/6/23/249', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://lkml.org/lkml/2005/6/24/173', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723', 'name': 'oval:org.mitre.oval:def:11723', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-663.html', 'name': 'RHSA-2005:663', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:219', 'name': 'MDKSA-2005:219', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}], 'descriptions': [{'lang': 'en', 'value': 'Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:235', 'name': 'MDKSA-2005:235', 'refsource': 'MANDRIVA'}, {'url': 'http://secunia.com/advisories/18684', 'name': '18684', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/18977', 'name': '18977', 'refsource': 'SECUNIA'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:220', 'name': 'MDKSA-2005:220', 'refsource': 'MANDRAKE'}, {'url': 'http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044', 'name': 'MDKSA-2006:044', 'refsource': 'MANDRIVA'}, {'url': 'http://www.securityfocus.com/bid/15528', 'name': '15528', 'refsource': 'BID'}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'refsource': 'DEBIAN'}, {'url': 'http://www.securityfocus.com/archive/1/427981/100/0/threaded', 'name': 'FLSA:157459-4', 'refsource': 'FEDORA'}, {'url': 'https://usn.ubuntu.com/219-1/', 'name': 'USN-219-1', 'refsource': 'UBUNTU'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0190.html', 'name': 'RHSA-2006:0190', 'refsource': 'REDHAT'}, {'url': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'name': 'http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d', 'refsource': 'CONFIRM'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:218', 'name': 'MDKSA-2005:218', 'refsource': 'MANDRAKE'}, {'url': 'http://secunia.com/advisories/17826', 'name': '17826', 'refsource': 'SECUNIA'}, {'url': 'http://lkml.org/lkml/2005/6/23/249', 'name': 'http://lkml.org/lkml/2005/6/23/249', 'refsource': 'CONFIRM'}, {'url': 'http://lkml.org/lkml/2005/6/24/173', 'name': 'http://lkml.org/lkml/2005/6/24/173', 'refsource': 'CONFIRM'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11723', 'name': 'oval:org.mitre.oval:def:11723', 'refsource': 'OVAL'}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'refsource': 'FEDORA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-663.html', 'name': 'RHSA-2005:663', 'refsource': 'REDHAT'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2005:219', 'name': 'MDKSA-2005:219', 'refsource': 'MANDRAKE'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3274', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3274', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-15T14:15:02.658Z', 'dateReserved': '2005-10-20T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-10-20T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-4650
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
none
yes
partial
2.0.3
2025-01-16 22:56:15.505761+03:00
['CWE-770']
2025-01-16 22:56:05.410000+03:00
64426efdf8b70ffbbe19fb28855e2d9917b930f33c07bfa23fba627efe219d76
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/21041', 'name': '21041', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.joomla.org/content/view/499/66/', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17675', 'name': '17675', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:53:28.563Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4650', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:56:15.505761Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-770', 'description': 'CWE-770 Allocation of Resources Without Limits or Throttling'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:56:05.410Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.osvdb.org/21041', 'name': '21041', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.joomla.org/content/view/499/66/', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://secunia.com/advisories/17675', 'name': '17675', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}], 'descriptions': [{'lang': 'en', 'value': 'Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-01-14T01:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/21041', 'name': '21041', 'refsource': 'OSVDB'}, {'url': 'http://www.joomla.org/content/view/499/66/', 'name': 'http://www.joomla.org/content/view/499/66/', 'refsource': 'CONFIRM'}, {'url': 'http://secunia.com/advisories/17675', 'name': '17675', 'refsource': 'SECUNIA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4650', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4650', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:56:20.937Z', 'dateReserved': '2006-01-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-01-14T01:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2000-1245
none
no
partial
2.0.3
2024-08-29 18:37:49.712788+03:00
2024-08-29 18:38:36.769000+03:00
8ef725c2d84d675c1e5dd18ef39454afd040d45aa7049c43b6046e33b8f7f82f
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T05:53:28.406Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2000-1245', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-29T15:37:49.712788Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-29T15:38:36.769Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2010-04-05T15:15:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'name': 'http://www.novell.com/support/viewContent.do?externalId=3238588&sliceId=1', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2000-1245', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2000-1245', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-17T00:05:49.841Z', 'dateReserved': '2010-04-05T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2010-04-05T15:15:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2001-0331
none
yes
partial
2.0.3
2024-08-29 18:50:47.972234+03:00
2024-08-29 18:50:53.304000+03:00
53fba33dee04e44948f8bb4238bf921db3f4afca4076f9f396838279f680393d
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/1822', 'name': '1822', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/258632', 'name': 'VU#258632', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6502', 'name': 'irix-espd-bo(6502)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P', 'name': '20010501-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI', 'x_transferred']}, {'url': 'http://xforce.iss.net/alerts/advise76.php', 'name': '20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure', 'tags': ['third-party-advisory', 'x_refsource_ISS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/2714', 'name': '2714', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T16:21:19.150Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2001-0331', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-29T15:50:47.972234Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-29T15:50:53.304Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2001-05-09T00:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/1822', 'name': '1822', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.kb.cert.org/vuls/id/258632', 'name': 'VU#258632', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6502', 'name': 'irix-espd-bo(6502)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P', 'name': '20010501-01-P', 'tags': ['vendor-advisory', 'x_refsource_SGI']}, {'url': 'http://xforce.iss.net/alerts/advise76.php', 'name': '20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure', 'tags': ['third-party-advisory', 'x_refsource_ISS']}, {'url': 'http://www.securityfocus.com/bid/2714', 'name': '2714', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2024-08-08T16:14:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/1822', 'name': '1822', 'refsource': 'OSVDB'}, {'url': 'http://www.kb.cert.org/vuls/id/258632', 'name': 'VU#258632', 'refsource': 'CERT-VN'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/6502', 'name': 'irix-espd-bo(6502)', 'refsource': 'XF'}, {'url': 'ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P', 'name': '20010501-01-P', 'refsource': 'SGI'}, {'url': 'http://xforce.iss.net/alerts/advise76.php', 'name': '20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure', 'refsource': 'ISS'}, {'url': 'http://www.securityfocus.com/bid/2714', 'name': '2714', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2001-0331', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2001-0331', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-29T15:50:57.052Z', 'dateReserved': '2001-05-08T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2001-09-18T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0029
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-08-01 22:28:25.242481+03:00
['CWE-125']
2024-08-01 22:31:28.822000+03:00
9a6a1ef2a2a0920aa052dcc1ebc1b08b956a8aa9a46712518aaac9b3a6718964
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:56.695Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0029', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:28:25.242481Z'}}}], 'affected': [{'cpes': ['cpe:2.3:o:sgi:irix:5.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.1.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:xfs:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:5.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.0.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.1:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.2:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.3:*:*:*:*:*:*:*', 'cpe:2.3:o:sgi:irix:6.4:*:*:*:*:*:*:*'], 'vendor': 'sgi', 'product': 'irix', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T19:31:28.822Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'root privileges via buffer overflow in ordist command on SGI IRIX systems.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:27:27.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0029', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'root privileges via buffer overflow in ordist command on SGI IRIX systems.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0029', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0029', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-29T14:07:56.381Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0043
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-08-01 22:56:17.928328+03:00
['CWE-78']
2024-08-01 23:02:42.640000+03:00
0572e979b7462ee246e65d6335bdea2ebdf7709d31ca1d8e8a877e8a19d2adbd
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.295Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0043', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T19:56:17.928328Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:isc:inn:1.4sec:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.4sec2:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.4unoff3:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.4unoff4:*:*:*:*:*:*:*', 'cpe:2.3:a:isc:inn:1.5:*:*:*:*:*:*:*'], 'vendor': 'isc', 'product': 'inn', 'versions': [{'status': 'affected', 'version': '1.4sec'}, {'status': 'affected', 'version': '1.4sec2'}, {'status': 'affected', 'version': '1.4unoff3'}, {'status': 'affected', 'version': '1.4unoff4'}, {'status': 'affected', 'version': '1.5'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:a:netscape:news_server:1.1:*:*:*:*:*:*:*'], 'vendor': 'netscape', 'product': 'news_server', 'versions': [{'status': 'affected', 'version': '1.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:bsdi:bsd_os:2.1:*:*:*:*:*:*:*'], 'vendor': 'bsdi', 'product': 'bsd_os', 'versions': [{'status': 'affected', 'version': '2.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:caldera:openlinux:1.0:*:*:*:*:*:*:*'], 'vendor': 'caldera', 'product': 'openlinux', 'versions': [{'status': 'affected', 'version': '1.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:redhat:linux:4.0:*:*:*:*:*:*:*'], 'vendor': 'redhat', 'product': 'linux', 'versions': [{'status': 'affected', 'version': '4.0'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:o:redhat:linux:4.1:*:*:*:*:*:*:*'], 'vendor': 'redhat', 'product': 'linux', 'versions': [{'status': 'affected', 'version': '4.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:h:nec:goah_intrasv:1.1:*:*:*:*:*:*:*'], 'vendor': 'nec', 'product': 'goah_intrasv', 'versions': [{'status': 'affected', 'version': '1.1'}], 'defaultStatus': 'unknown'}, {'cpes': ['cpe:2.3:h:nec:goah_networksv:1.2:*:*:*:*:*:*:*', 'cpe:2.3:h:nec:goah_networksv:2.2:*:*:*:*:*:*:*', 'cpe:2.3:h:nec:goah_networksv:3.1:*:*:*:*:*:*:*'], 'vendor': 'nec', 'product': 'goah_networksv', 'versions': [{'status': 'affected', 'version': '1.2'}, {'status': 'affected', 'version': '2.2'}, {'status': 'affected', 'version': '3.1'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-78', 'description': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:02:42.640Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2022-08-17T06:31:06.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'name': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0043', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0043', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:03:35.981Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-10001
none
no
partial
2.0.3
2025-04-14 20:15:38.326553+03:00
2025-04-14 20:15:39.774000+03:00
082521f0f602e038522d33fbf0c2b9d1ee039f4b09351a12324e0a46245453ab
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://vuldb.com/?id.1022', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:23.500Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-10001', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-14T17:15:38.326553Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-14T17:15:39.774Z'}}], 'cna': {'tags': ['unsupported-when-assigned'], 'title': 'Netegrity SiteMinder Login smpwservicescgi.exe redirect', 'credits': [{'lang': 'en', 'value': 'Marc Ruef'}], 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}], 'affected': [{'vendor': 'Netegrity', 'product': 'SiteMinder', 'versions': [{'status': 'affected', 'version': '4.5.0'}, {'status': 'affected', 'version': '4.5.1'}]}], 'references': [{'url': 'https://vuldb.com/?id.1022', 'tags': ['x_refsource_MISC']}], 'x_generator': 'vuldb.com', 'descriptions': [{'lang': 'en', 'value': 'A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-601', 'description': 'CWE-601 Open Redirect'}]}], 'providerMetadata': {'orgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'shortName': 'VulDB', 'dateUpdated': '2022-03-28T20:45:47.000Z'}, 'x_legacyV4Record': {'credit': 'Marc Ruef', 'impact': {'cvss': {'version': '3.1', 'baseScore': '5.4', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}}, 'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': '4.5.0'}, {'version_value': '4.5.1'}]}, 'product_name': 'SiteMinder'}]}, 'vendor_name': 'Netegrity'}]}}, 'data_type': 'CVE', 'generator': 'vuldb.com', 'references': {'reference_data': [{'url': 'https://vuldb.com/?id.1022', 'name': 'https://vuldb.com/?id.1022', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'CWE-601 Open Redirect'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-10001', 'STATE': 'PUBLIC', 'TITLE': 'Netegrity SiteMinder Login smpwservicescgi.exe redirect', 'ASSIGNER': 'cna@vuldb.com', 'REQUESTER': 'cna@vuldb.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-10001', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-15T14:45:26.644Z', 'dateReserved': '2022-01-28T00:00:00.000Z', 'assignerOrgId': '1af790b2-7ee1-4545-860a-a788eba489b5', 'datePublished': '2022-03-28T20:45:47.000Z', 'assignerShortName': 'VulDB'}, 'dataVersion': '5.1'}
CVE-2004-1901
5.50
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
none
no
partial
2.0.3
2024-01-31 18:42:15.161093+03:00
['CWE-59']
2025-01-16 21:09:20.441000+03:00
59a908b65a90e96efac7c0b926b3418e0ac8dbf22021abd27f365d5c45151c04
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/10060', 'name': '10060', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://security.gentoo.org/glsa/glsa-200404-01.xml', 'name': 'GLSA-200404-01', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'http://secunia.com/advisories/11305', 'name': '11305', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15754', 'name': 'portage-lockfile-hardlink(15754)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T01:07:49.064Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-1901', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-31T15:42:15.161093Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-59', 'description': "CWE-59 Improper Link Resolution Before File Access ('Link Following')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:09:20.441Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-04-06T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/10060', 'name': '10060', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://security.gentoo.org/glsa/glsa-200404-01.xml', 'name': 'GLSA-200404-01', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'http://secunia.com/advisories/11305', 'name': '11305', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15754', 'name': 'portage-lockfile-hardlink(15754)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/10060', 'name': '10060', 'refsource': 'BID'}, {'url': 'http://security.gentoo.org/glsa/glsa-200404-01.xml', 'name': 'GLSA-200404-01', 'refsource': 'GENTOO'}, {'url': 'http://secunia.com/advisories/11305', 'name': '11305', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15754', 'name': 'portage-lockfile-hardlink(15754)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-1901', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-1901', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:09:40.758Z', 'dateReserved': '2005-05-04T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-05-10T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-0367
7.80
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
active
no
total
2.0.3
2025-02-07 17:33:43.942338+03:00
['CWE-269']
2025-02-07 17:33:33.461000+03:00
6f6ff763c6ec8f5ac97227b50875bebe466261e4a53155718c4d7d9309b3d090
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/264441', 'name': '20020326 Re: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=ntbugtraq&m=101614320402695&w=2', 'name': '20020314 DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/4287', 'name': '4287', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024', 'name': 'MS02-024', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/264927', 'name': '20020327 Local Security Vulnerability in Windows NT and Windows 2000', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76', 'name': 'oval:org.mitre.oval:def:76', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/262074', 'name': '20020314 Fwd: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/8462.php', 'name': 'win-debug-duplicate-handles(8462)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158', 'name': 'oval:org.mitre.oval:def:158', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T02:49:28.090Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-0367', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:33:43.942338Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-03-03', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367'}}}], 'timeline': [{'lang': 'en', 'time': '2022-03-03T00:00:00.000Z', 'value': 'CVE-2002-0367 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-269', 'description': 'CWE-269 Improper Privilege Management'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:33:33.461Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2002-03-14T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/264441', 'name': '20020326 Re: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=ntbugtraq&m=101614320402695&w=2', 'name': '20020314 DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_NTBUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/4287', 'name': '4287', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024', 'name': 'MS02-024', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.securityfocus.com/archive/1/264927', 'name': '20020327 Local Security Vulnerability in Windows NT and Windows 2000', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76', 'name': 'oval:org.mitre.oval:def:76', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/archive/1/262074', 'name': '20020314 Fwd: DebPloit (exploit)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.iss.net/security_center/static/8462.php', 'name': 'win-debug-duplicate-handles(8462)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158', 'name': 'oval:org.mitre.oval:def:158', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}], 'descriptions': [{'lang': 'en', 'value': 'smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2002-06-11T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/264441', 'name': '20020326 Re: DebPloit (exploit)', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=ntbugtraq&m=101614320402695&w=2', 'name': '20020314 DebPloit (exploit)', 'refsource': 'NTBUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/4287', 'name': '4287', 'refsource': 'BID'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024', 'name': 'MS02-024', 'refsource': 'MS'}, {'url': 'http://www.securityfocus.com/archive/1/264927', 'name': '20020327 Local Security Vulnerability in Windows NT and Windows 2000', 'refsource': 'BUGTRAQ'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76', 'name': 'oval:org.mitre.oval:def:76', 'refsource': 'OVAL'}, {'url': 'http://www.securityfocus.com/archive/1/262074', 'name': '20020314 Fwd: DebPloit (exploit)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.iss.net/security_center/static/8462.php', 'name': 'win-debug-duplicate-handles(8462)', 'refsource': 'XF'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158', 'name': 'oval:org.mitre.oval:def:158', 'refsource': 'OVAL'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-0367', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-0367', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.464Z', 'dateReserved': '2002-05-08T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2003-04-02T05:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0066
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-08-01 23:49:31.626761+03:00
2024-08-01 23:50:25.247000+03:00
dd5b75aa4b8c1600705185af6bf55f28a12eaf50a429382e32b45cbcdfbfd560
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/719', 'name': '719', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:27:57.424Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0066', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-08-01T20:49:31.626761Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:john_s._roberts:anyform:1.0:*:*:*:*:*:*:*', 'cpe:2.3:a:john_s._roberts:anyform:2.0:*:*:*:*:*:*:*'], 'vendor': 'john_s._roberts', 'product': 'anyform', 'versions': [{'status': 'affected', 'version': '1.0'}, {'status': 'affected', 'version': '2.0'}], 'defaultStatus': 'unknown'}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T20:50:25.247Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/bid/719', 'name': '719', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'AnyForm CGI remote execution.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/719', 'name': '719', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'AnyForm CGI remote execution.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0066', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0066', 'state': 'PUBLISHED', 'dateUpdated': '2024-08-01T20:50:29.555Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2002-2024
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
none
yes
partial
2.0.3
2024-08-08 17:02:22.048868+03:00
['CWE-219']
2024-08-08 17:06:31.744000+03:00
d8fbcd1ee0abb01ca0f1e6e9309a82d3bf1a7a2d3fddf4cb49ef04281a7b05a0
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://bugs.horde.org/show_bug.cgi?id=916', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/4445', 'name': '4445', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.iss.net/security_center/static/8768.php', 'name': 'imp-php-path-disclosure(8768)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T03:51:17.588Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2002-2024', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-08T14:02:22.048868Z'}}}], 'affected': [{'cpes': ['cpe:2.3:a:horde:imp:2.2.7:*:*:*:*:*:*:*'], 'vendor': 'horde', 'product': 'imp', 'versions': [{'status': 'affected', 'version': '2.2.7'}], 'defaultStatus': 'unknown'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-219', 'description': 'CWE-219 Storage of File with Sensitive Data Under Web Root'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-08T14:06:31.744Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://bugs.horde.org/show_bug.cgi?id=916', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/4445', 'name': '4445', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.iss.net/security_center/static/8768.php', 'name': 'imp-php-path-disclosure(8768)', 'tags': ['vdb-entry', 'x_refsource_XF']}], 'descriptions': [{'lang': 'en', 'value': 'Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-07-14T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://bugs.horde.org/show_bug.cgi?id=916', 'name': 'http://bugs.horde.org/show_bug.cgi?id=916', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/4445', 'name': '4445', 'refsource': 'BID'}, {'url': 'http://www.iss.net/security_center/static/8768.php', 'name': 'imp-php-path-disclosure(8768)', 'refsource': 'XF'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2002-2024', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2002-2024', 'state': 'PUBLISHED', 'dateUpdated': '2024-09-16T18:24:20.639Z', 'dateReserved': '2005-07-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-07-14T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-1999-0468
8.20
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
none
no
partial
2.0.3
2025-08-25 21:47:58.178455+03:00
['CWE-200']
2025-08-25 21:51:42.771000+03:00
9e13f42383a267d48544afb1f3bbdb038bd20776ea7c0f85ae2e95a51c509c9e
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012', 'name': 'MS99-012', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-01T16:41:45.411Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-1999-0468', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-08-25T18:47:58.178455Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-200', 'description': 'CWE-200 Exposure of Sensitive Information to an Unauthorized Actor'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-08-25T18:51:42.771Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012', 'name': 'MS99-012', 'tags': ['vendor-advisory', 'x_refsource_MS']}], 'descriptions': [{'lang': 'en', 'value': "Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-11-02T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012', 'name': 'MS99-012', 'refsource': 'MS'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-1999-0468', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-1999-0468', 'state': 'PUBLISHED', 'dateUpdated': '2025-08-25T18:51:48.046Z', 'dateReserved': '1999-06-07T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '1999-09-29T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-2773
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
active
yes
total
2.0.3
2025-02-07 17:28:10.470925+03:00
['CWE-77']
2025-02-07 17:28:03.285000+03:00
df9ad05baad849ceedf98162c9d9a27d826f6b5fbcea35dccc2965197d17179e
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=112499121725662&w=2', 'name': '20050825 Portcullis Security Advisory 05-014 HP Openview Remote Command', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/21999', 'name': 'hp-openview-node-manager-command-execution(21999)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'HPSBMA01224', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/14662', 'name': '14662', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/16555/', 'name': '16555', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'SSRT051023', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:45:02.175Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-2773', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T14:28:10.470925Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-03-25', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773'}}}], 'timeline': [{'lang': 'en', 'time': '2022-03-25T00:00:00.000Z', 'value': 'CVE-2005-2773 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-77', 'description': "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T14:28:03.285Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-08-25T00:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=112499121725662&w=2', 'name': '20050825 Portcullis Security Advisory 05-014 HP Openview Remote Command', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/21999', 'name': 'hp-openview-node-manager-command-execution(21999)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'HPSBMA01224', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.securityfocus.com/bid/14662', 'name': '14662', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/16555/', 'name': '16555', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'SSRT051023', 'tags': ['vendor-advisory', 'x_refsource_HP']}], 'descriptions': [{'lang': 'en', 'value': 'HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-10T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=112499121725662&w=2', 'name': '20050825 Portcullis Security Advisory 05-014 HP Openview Remote Command', 'refsource': 'BUGTRAQ'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/21999', 'name': 'hp-openview-node-manager-command-execution(21999)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'HPSBMA01224', 'refsource': 'HP'}, {'url': 'http://www.securityfocus.com/bid/14662', 'name': '14662', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/16555/', 'name': '16555', 'refsource': 'SECUNIA'}, {'url': 'http://www.securityfocus.com/advisories/9150', 'name': 'SSRT051023', 'refsource': 'HP'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-2773', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-2773', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:57.013Z', 'dateReserved': '2005-09-02T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-09-02T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-3170
5.00
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
none
no
partial
2.0.3
2024-10-15 17:14:19.553033+03:00
['CWE-295']
2024-10-15 17:14:23.499000+03:00
ab9f69c4726888fa320091ef33b863ce8865e0d13a8d34255ac90421b27e32a8
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://support.microsoft.com/kb/883639', 'name': '883639', 'tags': ['vendor-advisory', 'x_refsource_MSKB', 'x_transferred']}, {'url': 'http://support.microsoft.com/kb/900345', 'name': '900345', 'tags': ['vendor-advisory', 'x_refsource_MSKB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:01:58.781Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3170', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-10-15T14:14:19.553033Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-295', 'description': 'CWE-295 Improper Certificate Validation'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-15T14:14:23.499Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://support.microsoft.com/kb/883639', 'name': '883639', 'tags': ['vendor-advisory', 'x_refsource_MSKB']}, {'url': 'http://support.microsoft.com/kb/900345', 'name': '900345', 'tags': ['vendor-advisory', 'x_refsource_MSKB']}], 'descriptions': [{'lang': 'en', 'value': 'The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-10-06T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://support.microsoft.com/kb/883639', 'name': '883639', 'refsource': 'MSKB'}, {'url': 'http://support.microsoft.com/kb/900345', 'name': '900345', 'refsource': 'MSKB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3170', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3170', 'state': 'PUBLISHED', 'dateUpdated': '2024-12-05T20:28:56.956Z', 'dateReserved': '2005-10-06T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-10-06T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-3302
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
partial
2.0.3
2025-01-16 22:46:14.945366+03:00
['CWE-94']
2025-01-16 22:46:04.151000+03:00
27de896e0a96b4e1e180d112a72ce1e5ce137a488f5f6d02a81204a85d009c74
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://secunia.com/advisories/19754', 'name': '19754', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/17663', 'name': '17663', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.debian.org/security/2006/dsa-1039', 'name': 'DSA-1039', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:10:07.636Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3302', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:46:14.945366Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:46:04.151Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-09-30T00:00:00.000Z', 'references': [{'url': 'http://secunia.com/advisories/19754', 'name': '19754', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securityfocus.com/bid/17663', 'name': '17663', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.debian.org/security/2006/dsa-1039', 'name': 'DSA-1039', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-04-26T09:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://secunia.com/advisories/19754', 'name': '19754', 'refsource': 'SECUNIA'}, {'url': 'http://www.securityfocus.com/bid/17663', 'name': '17663', 'refsource': 'BID'}, {'url': 'http://www.debian.org/security/2006/dsa-1039', 'name': 'DSA-1039', 'refsource': 'DEBIAN'}, {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'name': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3302', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3302', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:46:53.131Z', 'dateReserved': '2005-10-24T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-10-24T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-2103
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-02-06 00:54:23.938897+03:00
['CWE-131']
2025-01-16 22:43:38.293000+03:00
864080307acb559a00978394e7f84339b066204c371c3a5eb88f6a610578f4ca
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://gaim.sourceforge.net/security/?id=22', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/426078/100/0/threaded', 'name': 'FLSA:158543', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2005_19_sr.html', 'name': 'SUSE-SR:2005:019', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11477', 'name': 'oval:org.mitre.oval:def:11477', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/14531', 'name': '14531', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://usn.ubuntu.com/168-1/', 'name': 'USN-168-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-627.html', 'name': 'RHSA-2005:627', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-589.html', 'name': 'RHSA-2005:589', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:15:37.427Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-2103', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-05T21:54:23.938897Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-131', 'description': 'CWE-131 Incorrect Calculation of Buffer Size'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:43:38.293Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-08-12T04:00:00.000Z', 'references': [{'url': 'http://gaim.sourceforge.net/security/?id=22', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/archive/1/426078/100/0/threaded', 'name': 'FLSA:158543', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.novell.com/linux/security/advisories/2005_19_sr.html', 'name': 'SUSE-SR:2005:019', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11477', 'name': 'oval:org.mitre.oval:def:11477', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/bid/14531', 'name': '14531', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://usn.ubuntu.com/168-1/', 'name': 'USN-168-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-627.html', 'name': 'RHSA-2005:627', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-589.html', 'name': 'RHSA-2005:589', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2018-10-19T18:57:01.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2005-2103', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:43:45.313Z', 'dateReserved': '2005-06-30T04:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2005-08-16T08:00:00.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'}
CVE-2005-1831
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2024-04-15 22:19:25.314836+03:00
2025-01-16 22:09:07.904000+03:00
f33fc56ed2233725682a0aa78969870877f8ca05fee4d1522e5e57fea22d9a29
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html', 'name': '20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html', 'name': '20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111755694008928&w=2', 'name': '20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/20417', 'name': '20417', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:06:57.739Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1831', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-04-15T19:19:25.314836Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:09:07.904Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-05-31T04:00:00.000Z', 'references': [{'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html', 'name': '20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html', 'name': '20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://marc.info/?l=bugtraq&m=111755694008928&w=2', 'name': '20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/20417', 'name': '20417', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don\'t see how this could happen unless the user\'s actual password was empty.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html', 'name': '20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'refsource': 'BUGTRAQ'}, {'url': 'http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html', 'name': '20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'refsource': 'BUGTRAQ'}, {'url': 'http://marc.info/?l=bugtraq&m=111755694008928&w=2', 'name': '20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/20417', 'name': '20417', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don\'t see how this could happen unless the user\'s actual password was empty."'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1831', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1831', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:09:52.691Z', 'dateReserved': '2005-06-02T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-02T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-1688
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
none
yes
partial
2.0.3
2025-01-16 21:41:43.843484+03:00
['CWE-425']
2025-01-16 21:43:38.674000+03:00
ea51426a68f8f7f22c053332f11d9f48942a815134e6194ab96ac6c8d79d2f95
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=111661517716733&w=2', 'name': '20050520 [BuHa Security] Wordpress SQL-Injection', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:59:24.035Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1688', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T18:41:43.843484Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-425', 'description': "CWE-425 Direct Request ('Forced Browsing')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:43:38.674Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-05-20T04:00:00.000Z', 'references': [{'url': 'http://marc.info/?l=bugtraq&m=111661517716733&w=2', 'name': '20050520 [BuHa Security] Wordpress SQL-Injection', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://marc.info/?l=bugtraq&m=111661517716733&w=2', 'name': '20050520 [BuHa Security] Wordpress SQL-Injection', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1688', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1688', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:43:51.233Z', 'dateReserved': '2005-05-20T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-05-25T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-1674
6.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
none
no
partial
2.0.3
2025-01-16 21:10:54.662454+03:00
['CWE-352']
2025-01-16 21:10:27.407000+03:00
6e3a386538bdca79a80abbbb706ceca7a7fdac3b11fd72eeab5bdb3c3d5fd204
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0', 'name': '20050517 Help Center Live Vulnerabilities', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T21:59:23.943Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1674', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T18:10:54.662454Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-352', 'description': 'CWE-352 Cross-Site Request Forgery (CSRF)'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T18:10:27.407Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0', 'name': '20050517 Help Center Live Vulnerabilities', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2005-05-19T04:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'name': 'http://www.gulftech.org/?node=research&article_id=00076-05172005', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0', 'name': '20050517 Help Center Live Vulnerabilities', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1674', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1674', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T18:10:58.838Z', 'dateReserved': '2005-05-19T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-05-19T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2004-0079
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2024-01-08 19:21:54.985893+03:00
['CWE-476']
2025-01-16 20:31:06.392000+03:00
3cd140c66c643d8d153aaa1e75051ba13a5a229de5fc325d887ea87e56f9bcc0
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/9899', 'name': '9899', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html', 'name': 'FEDORA-2005-1042', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html', 'name': 'ESA-20040317-003', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=108403806509920&w=2', 'name': 'SSRT4717', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-121.html', 'name': 'RHSA-2004:121', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2004:023', 'name': 'MDKSA-2004:023', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621', 'name': 'oval:org.mitre.oval:def:2621', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834', 'name': 'CLA-2004:834', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA', 'x_transferred']}, {'url': 'ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt', 'name': 'SCOSA-2004.10', 'tags': ['vendor-advisory', 'x_refsource_SCO', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17381', 'name': '17381', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://fedoranews.org/updates/FEDORA-2004-095.shtml', 'name': 'FEDORA-2004-095', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779', 'name': 'oval:org.mitre.oval:def:9779', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975', 'name': 'oval:org.mitre.oval:def:975', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524', 'name': '57524', 'tags': ['vendor-advisory', 'x_refsource_SUNALERT', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2004_07_openssl.html', 'name': 'SuSE-SA:2004:007', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.openssl.org/news/secadv_20040317.txt', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc', 'name': 'FreeBSD-SA-04:05', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD', 'x_transferred']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc', 'name': 'NetBSD-SA2004-005', 'tags': ['vendor-advisory', 'x_refsource_NETBSD', 'x_transferred']}, {'url': 'http://www.ciac.org/ciac/bulletins/o-101.shtml', 'name': 'O-101', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA04-078A.html', 'name': 'TA04-078A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17401', 'name': '17401', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-829.html', 'name': 'RHSA-2005:829', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870', 'name': 'oval:org.mitre.oval:def:870', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-830.html', 'name': 'RHSA-2005:830', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://security.gentoo.org/glsa/glsa-200403-03.xml', 'name': 'GLSA-200403-03', 'tags': ['vendor-advisory', 'x_refsource_GENTOO', 'x_transferred']}, {'url': 'http://secunia.com/advisories/11139', 'name': '11139', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-120.html', 'name': 'RHSA-2004:120', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=107953412903636&w=2', 'name': '20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html', 'name': 'APPLE-SA-2005-08-15', 'tags': ['vendor-advisory', 'x_refsource_APPLE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17398', 'name': '17398', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961', 'name': 'SSA:2004-077', 'tags': ['vendor-advisory', 'x_refsource_SLACKWARE', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-139.html', 'name': 'RHSA-2004:139', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15505', 'name': 'openssl-dochangecipherspec-dos(15505)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.trustix.org/errata/2004/0012', 'name': '2004-0012', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX', 'x_transferred']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml', 'name': '20040317 Cisco OpenSSL Implementation Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://docs.info.apple.com/article.html?artnum=61798', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/288574', 'name': 'VU#288574', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.debian.org/security/2004/dsa-465', 'name': 'DSA-465', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html', 'name': 'APPLE-SA-2005-08-17', 'tags': ['vendor-advisory', 'x_refsource_APPLE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18247', 'name': '18247', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770', 'name': 'oval:org.mitre.oval:def:5770', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:23.689Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2004-0079', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-01-08T16:21:54.985893Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-476', 'description': 'CWE-476 NULL Pointer Dereference'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T17:31:06.392Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2004-03-17T05:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/9899', 'name': '9899', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html', 'name': 'FEDORA-2005-1042', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html', 'name': 'ESA-20040317-003', 'tags': ['vendor-advisory', 'x_refsource_ENGARDE']}, {'url': 'http://marc.info/?l=bugtraq&m=108403806509920&w=2', 'name': 'SSRT4717', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-121.html', 'name': 'RHSA-2004:121', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2004:023', 'name': 'MDKSA-2004:023', 'tags': ['vendor-advisory', 'x_refsource_MANDRAKE']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621', 'name': 'oval:org.mitre.oval:def:2621', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834', 'name': 'CLA-2004:834', 'tags': ['vendor-advisory', 'x_refsource_CONECTIVA']}, {'url': 'ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt', 'name': 'SCOSA-2004.10', 'tags': ['vendor-advisory', 'x_refsource_SCO']}, {'url': 'http://secunia.com/advisories/17381', 'name': '17381', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'tags': ['x_refsource_MISC']}, {'url': 'http://fedoranews.org/updates/FEDORA-2004-095.shtml', 'name': 'FEDORA-2004-095', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779', 'name': 'oval:org.mitre.oval:def:9779', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975', 'name': 'oval:org.mitre.oval:def:975', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524', 'name': '57524', 'tags': ['vendor-advisory', 'x_refsource_SUNALERT']}, {'url': 'http://www.novell.com/linux/security/advisories/2004_07_openssl.html', 'name': 'SuSE-SA:2004:007', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.openssl.org/news/secadv_20040317.txt', 'tags': ['x_refsource_CONFIRM']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc', 'name': 'FreeBSD-SA-04:05', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD']}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc', 'name': 'NetBSD-SA2004-005', 'tags': ['vendor-advisory', 'x_refsource_NETBSD']}, {'url': 'http://www.ciac.org/ciac/bulletins/o-101.shtml', 'name': 'O-101', 'tags': ['third-party-advisory', 'government-resource', 'x_refsource_CIAC']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA04-078A.html', 'name': 'TA04-078A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://secunia.com/advisories/17401', 'name': '17401', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-829.html', 'name': 'RHSA-2005:829', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870', 'name': 'oval:org.mitre.oval:def:870', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-830.html', 'name': 'RHSA-2005:830', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://security.gentoo.org/glsa/glsa-200403-03.xml', 'name': 'GLSA-200403-03', 'tags': ['vendor-advisory', 'x_refsource_GENTOO']}, {'url': 'http://secunia.com/advisories/11139', 'name': '11139', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-120.html', 'name': 'RHSA-2004:120', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://marc.info/?l=bugtraq&m=107953412903636&w=2', 'name': '20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html', 'name': 'APPLE-SA-2005-08-15', 'tags': ['vendor-advisory', 'x_refsource_APPLE']}, {'url': 'http://secunia.com/advisories/17398', 'name': '17398', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961', 'name': 'SSA:2004-077', 'tags': ['vendor-advisory', 'x_refsource_SLACKWARE']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-139.html', 'name': 'RHSA-2004:139', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15505', 'name': 'openssl-dochangecipherspec-dos(15505)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.trustix.org/errata/2004/0012', 'name': '2004-0012', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX']}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml', 'name': '20040317 Cisco OpenSSL Implementation Vulnerability', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://docs.info.apple.com/article.html?artnum=61798', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.kb.cert.org/vuls/id/288574', 'name': 'VU#288574', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.debian.org/security/2004/dsa-465', 'name': 'DSA-465', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html', 'name': 'APPLE-SA-2005-08-17', 'tags': ['vendor-advisory', 'x_refsource_APPLE']}, {'url': 'http://secunia.com/advisories/18247', 'name': '18247', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770', 'name': 'oval:org.mitre.oval:def:5770', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}], 'descriptions': [{'lang': 'en', 'value': 'The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-10-10T04:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/9899', 'name': '9899', 'refsource': 'BID'}, {'url': 'http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html', 'name': 'FEDORA-2005-1042', 'refsource': 'FEDORA'}, {'url': 'http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html', 'name': 'ESA-20040317-003', 'refsource': 'ENGARDE'}, {'url': 'http://marc.info/?l=bugtraq&m=108403806509920&w=2', 'name': 'SSRT4717', 'refsource': 'HP'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-121.html', 'name': 'RHSA-2004:121', 'refsource': 'REDHAT'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2004:023', 'name': 'MDKSA-2004:023', 'refsource': 'MANDRAKE'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621', 'name': 'oval:org.mitre.oval:def:2621', 'refsource': 'OVAL'}, {'url': 'http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834', 'name': 'CLA-2004:834', 'refsource': 'CONECTIVA'}, {'url': 'ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt', 'name': 'SCOSA-2004.10', 'refsource': 'SCO'}, {'url': 'http://secunia.com/advisories/17381', 'name': '17381', 'refsource': 'SECUNIA'}, {'url': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'name': 'http://www.uniras.gov.uk/vuls/2004/224012/index.htm', 'refsource': 'MISC'}, {'url': 'http://fedoranews.org/updates/FEDORA-2004-095.shtml', 'name': 'FEDORA-2004-095', 'refsource': 'FEDORA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779', 'name': 'oval:org.mitre.oval:def:9779', 'refsource': 'OVAL'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975', 'name': 'oval:org.mitre.oval:def:975', 'refsource': 'OVAL'}, {'url': 'http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524', 'name': '57524', 'refsource': 'SUNALERT'}, {'url': 'http://www.novell.com/linux/security/advisories/2004_07_openssl.html', 'name': 'SuSE-SA:2004:007', 'refsource': 'SUSE'}, {'url': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'name': 'http://lists.apple.com/mhonarc/security-announce/msg00045.html', 'refsource': 'CONFIRM'}, {'url': 'http://www.openssl.org/news/secadv_20040317.txt', 'name': 'http://www.openssl.org/news/secadv_20040317.txt', 'refsource': 'CONFIRM'}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc', 'name': 'FreeBSD-SA-04:05', 'refsource': 'FREEBSD'}, {'url': 'ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc', 'name': 'NetBSD-SA2004-005', 'refsource': 'NETBSD'}, {'url': 'http://www.ciac.org/ciac/bulletins/o-101.shtml', 'name': 'O-101', 'refsource': 'CIAC'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA04-078A.html', 'name': 'TA04-078A', 'refsource': 'CERT'}, {'url': 'http://secunia.com/advisories/17401', 'name': '17401', 'refsource': 'SECUNIA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-829.html', 'name': 'RHSA-2005:829', 'refsource': 'REDHAT'}, {'url': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'name': 'http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm', 'refsource': 'CONFIRM'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870', 'name': 'oval:org.mitre.oval:def:870', 'refsource': 'OVAL'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2005-830.html', 'name': 'RHSA-2005:830', 'refsource': 'REDHAT'}, {'url': 'http://security.gentoo.org/glsa/glsa-200403-03.xml', 'name': 'GLSA-200403-03', 'refsource': 'GENTOO'}, {'url': 'http://secunia.com/advisories/11139', 'name': '11139', 'refsource': 'SECUNIA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-120.html', 'name': 'RHSA-2004:120', 'refsource': 'REDHAT'}, {'url': 'http://marc.info/?l=bugtraq&m=107953412903636&w=2', 'name': '20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]', 'refsource': 'BUGTRAQ'}, {'url': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'name': 'http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US', 'refsource': 'CONFIRM'}, {'url': 'http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html', 'name': 'APPLE-SA-2005-08-15', 'refsource': 'APPLE'}, {'url': 'http://secunia.com/advisories/17398', 'name': '17398', 'refsource': 'SECUNIA'}, {'url': 'http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961', 'name': 'SSA:2004-077', 'refsource': 'SLACKWARE'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2004-139.html', 'name': 'RHSA-2004:139', 'refsource': 'REDHAT'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/15505', 'name': 'openssl-dochangecipherspec-dos(15505)', 'refsource': 'XF'}, {'url': 'http://www.trustix.org/errata/2004/0012', 'name': '2004-0012', 'refsource': 'TRUSTIX'}, {'url': 'http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml', 'name': '20040317 Cisco OpenSSL Implementation Vulnerability', 'refsource': 'CISCO'}, {'url': 'http://docs.info.apple.com/article.html?artnum=61798', 'name': 'http://docs.info.apple.com/article.html?artnum=61798', 'refsource': 'CONFIRM'}, {'url': 'http://www.kb.cert.org/vuls/id/288574', 'name': 'VU#288574', 'refsource': 'CERT-VN'}, {'url': 'http://www.debian.org/security/2004/dsa-465', 'name': 'DSA-465', 'refsource': 'DEBIAN'}, {'url': 'http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html', 'name': 'APPLE-SA-2005-08-17', 'refsource': 'APPLE'}, {'url': 'http://secunia.com/advisories/18247', 'name': '18247', 'refsource': 'SECUNIA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770', 'name': 'oval:org.mitre.oval:def:5770', 'refsource': 'OVAL'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2004-0079', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2004-0079', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T17:33:22.869Z', 'dateReserved': '2004-01-19T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2004-03-18T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-3106
4.70
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
none
no
partial
2.0.3
2024-02-16 19:17:54.787409+03:00
['CWE-667']
2025-01-16 22:44:22.117000+03:00
0fd02f8954416e4bedba0c70d2378b43d02206226c12a7dec70b1ef59e608a49
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9108', 'name': 'oval:org.mitre.oval:def:9108', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0101.html', 'name': 'RHSA-2006:0101', 'tags': ['vendor-advisory', 'x_refsource_REDHAT', 'x_transferred']}, {'url': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c%401.156?nav=index.html%7Csrc/%7Csrc/fs%7Chist/fs/exec.c', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/15049', 'name': '15049', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18510', 'name': '18510', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17141', 'name': '17141', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-199-1', 'name': 'USN-199-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2006:072', 'name': 'MDKSA-2006:072', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:01:57.774Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-3106', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-16T16:17:54.787409Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-667', 'description': 'CWE-667 Improper Locking'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:44:22.117Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-09-29T00:00:00.000Z', 'references': [{'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9108', 'name': 'oval:org.mitre.oval:def:9108', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0101.html', 'name': 'RHSA-2006:0101', 'tags': ['vendor-advisory', 'x_refsource_REDHAT']}, {'url': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c%401.156?nav=index.html%7Csrc/%7Csrc/fs%7Chist/fs/exec.c', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'tags': ['vendor-advisory', 'x_refsource_DEBIAN']}, {'url': 'http://www.securityfocus.com/bid/15049', 'name': '15049', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/18510', 'name': '18510', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/17141', 'name': '17141', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.ubuntu.com/usn/usn-199-1', 'name': 'USN-199-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2006:072', 'name': 'MDKSA-2006:072', 'tags': ['vendor-advisory', 'x_refsource_MANDRIVA']}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'tags': ['vendor-advisory', 'x_refsource_FEDORA']}], 'descriptions': [{'lang': 'en', 'value': 'Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9108', 'name': 'oval:org.mitre.oval:def:9108', 'refsource': 'OVAL'}, {'url': 'http://secunia.com/advisories/18056', 'name': '18056', 'refsource': 'SECUNIA'}, {'url': 'http://www.redhat.com/support/errata/RHSA-2006-0101.html', 'name': 'RHSA-2006:0101', 'refsource': 'REDHAT'}, {'url': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c@1.156?nav=index.html|src/|src/fs|hist/fs/exec.c', 'name': 'http://linux.bkbits.net:8080/linux-2.6/diffs/fs/exec.c@1.156?nav=index.html|src/|src/fs|hist/fs/exec.c', 'refsource': 'CONFIRM'}, {'url': 'http://www.debian.org/security/2005/dsa-922', 'name': 'DSA-922', 'refsource': 'DEBIAN'}, {'url': 'http://www.securityfocus.com/bid/15049', 'name': '15049', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/18510', 'name': '18510', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/17141', 'name': '17141', 'refsource': 'SECUNIA'}, {'url': 'http://www.ubuntu.com/usn/usn-199-1', 'name': 'USN-199-1', 'refsource': 'UBUNTU'}, {'url': 'http://www.mandriva.com/security/advisories?name=MDKSA-2006:072', 'name': 'MDKSA-2006:072', 'refsource': 'MANDRIVA'}, {'url': 'http://www.securityfocus.com/archive/1/427980/100/0/threaded', 'name': 'FLSA:157459-3', 'refsource': 'FEDORA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-3106', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-3106', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:44:38.257Z', 'dateReserved': '2005-09-30T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-09-30T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-1794
7.40
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
none
no
total
2.0.3
2026-05-22 13:32:10.235169+03:00
2026-05-22 13:32:00.457000+03:00
179581b01d8de88bd0b2010be8adc5f4efc4e08e2f477487fd8de6391830f029
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://secunia.com/advisories/15605/', 'name': '15605', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/13818', 'name': '13818', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441', 'name': 'oval:org.mitre.oval:def:12441', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:06:56.561Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1794', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-22T10:32:10.235169Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-22T10:32:00.457Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-05-28T00:00:00.000Z', 'references': [{'url': 'http://secunia.com/advisories/15605/', 'name': '15605', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/13818', 'name': '13818', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'tags': ['x_refsource_MISC']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441', 'name': 'oval:org.mitre.oval:def:12441', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}], 'descriptions': [{'lang': 'en', 'value': 'Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-03-27T15:57:02.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://secunia.com/advisories/15605/', 'name': '15605', 'refsource': 'SECUNIA'}, {'url': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'name': 'http://www.oxid.it/downloads/rdp-gbu.pdf', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/13818', 'name': '13818', 'refsource': 'BID'}, {'url': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'name': 'https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02', 'refsource': 'MISC'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441', 'name': 'oval:org.mitre.oval:def:12441', 'refsource': 'OVAL'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1794', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1794', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-22T10:33:57.094Z', 'dateReserved': '2005-06-01T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-01T04:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-2006-0149
6.10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
none
no
partial
2.0.3
2025-04-03 17:52:41.844258+03:00
['CWE-80']
2025-04-03 17:54:25.932000+03:00
4b0aa1157ec76dba7b58fbb1e51d6326db4d4d13f2753873f375de36d160b5f7
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securitytracker.com/id?1015451', 'name': '1015451', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html', 'name': '20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability', 'tags': ['mailing-list', 'x_refsource_FULLDISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:25:34.057Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-0149', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-03T14:52:41.844258Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-80', 'description': 'CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T14:54:25.932Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://securitytracker.com/id?1015451', 'name': '1015451', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html', 'name': '20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability', 'tags': ['mailing-list', 'x_refsource_FULLDISC']}], 'descriptions': [{'lang': 'en', 'value': 'Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-01-09T23:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://securitytracker.com/id?1015451', 'name': '1015451', 'refsource': 'SECTRACK'}, {'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html', 'name': '20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability', 'refsource': 'FULLDISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-0149', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-0149', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T14:56:57.175Z', 'dateReserved': '2006-01-09T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-01-09T23:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-1876
4.50
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
none
no
total
2.0.3
2024-02-14 18:46:22.530197+03:00
['CWE-94']
2025-01-16 22:11:19.635000+03:00
2224a0f3c096a50ae62bbe7910c0427c89cf34094f208759cc84c6e5d5fa9c35
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/17030', 'name': '17030', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=111773528322711&w=2', 'name': '20050602 PHP Execution Vulnerability in CuteNews', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/15594', 'name': '15594', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T22:06:57.133Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-1876', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-02-14T15:46:22.530197Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:11:19.635Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-06-02T04:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/17030', 'name': '17030', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://marc.info/?l=bugtraq&m=111773528322711&w=2', 'name': '20050602 PHP Execution Vulnerability in CuteNews', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/15594', 'name': '15594', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}], 'descriptions': [{'lang': 'en', 'value': 'Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2016-10-17T17:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/17030', 'name': '17030', 'refsource': 'OSVDB'}, {'url': 'http://marc.info/?l=bugtraq&m=111773528322711&w=2', 'name': '20050602 PHP Execution Vulnerability in CuteNews', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/15594', 'name': '15594', 'refsource': 'SECUNIA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-1876', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-1876', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:13:11.881Z', 'dateReserved': '2005-06-08T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-06-07T08:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-4206
6.10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
none
no
partial
2.0.3
2025-01-16 22:48:32.555946+03:00
['CWE-601']
2025-01-16 22:48:13.868000+03:00
1fa4ccf9f0ee869dfe54ee923aaaa1a4fb13fc38091ab71eadd51789b7fe9fca
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23558', 'name': 'academicsuite-frameset-crossdomain-loading(23558)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://secunia.com/advisories/17991', 'name': '17991', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.osvdb.org/21618', 'name': '21618', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/15814', 'name': '15814', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:38:51.545Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4206', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T19:48:32.555946Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-601', 'description': "CWE-601 URL Redirection to Untrusted Site ('Open Redirect')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:48:13.868Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-11-16T00:00:00.000Z', 'references': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23558', 'name': 'academicsuite-frameset-crossdomain-loading(23558)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'tags': ['x_refsource_MISC']}, {'url': 'http://secunia.com/advisories/17991', 'name': '17991', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.osvdb.org/21618', 'name': '21618', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/15814', 'name': '15814', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23558', 'name': 'academicsuite-frameset-crossdomain-loading(23558)', 'refsource': 'XF'}, {'url': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'name': 'http://www.ipomonis.com/advisories/Bb_6.zip', 'refsource': 'MISC'}, {'url': 'http://secunia.com/advisories/17991', 'name': '17991', 'refsource': 'SECUNIA'}, {'url': 'http://www.osvdb.org/21618', 'name': '21618', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/15814', 'name': '15814', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4206', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4206', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:48:36.106Z', 'dateReserved': '2005-12-13T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-12-13T11:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-0054
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
none
yes
partial
2.0.3
2024-02-14 19:15:16.514845+03:00
['CWE-824']
2025-01-16 22:52:58.803000+03:00
0b63d49549fec1e932c806e283ae4961a143081600e55257a2cce16a0306e02e
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/22319', 'name': '22319', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/16209', 'name': '16209', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18378', 'name': '18378', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24073', 'name': 'ipfw-icmp-fragment-dos(24073)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc', 'name': 'FreeBSD-SA-06:04', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1015477', 'name': '1015477', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:18:20.791Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-0054', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-02-14T16:15:16.514845Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-824', 'description': 'CWE-824 Access of Uninitialized Pointer'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:52:58.803Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-01-11T00:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/22319', 'name': '22319', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/16209', 'name': '16209', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/18378', 'name': '18378', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24073', 'name': 'ipfw-icmp-fragment-dos(24073)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc', 'name': 'FreeBSD-SA-06:04', 'tags': ['vendor-advisory', 'x_refsource_FREEBSD']}, {'url': 'http://securitytracker.com/id?1015477', 'name': '1015477', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}], 'descriptions': [{'lang': 'en', 'value': 'The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '63664ac6-956c-4cba-a5d0-f46076e16109', 'shortName': 'freebsd', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/22319', 'name': '22319', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/16209', 'name': '16209', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/18378', 'name': '18378', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24073', 'name': 'ipfw-icmp-fragment-dos(24073)', 'refsource': 'XF'}, {'url': 'ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc', 'name': 'FreeBSD-SA-06:04', 'refsource': 'FREEBSD'}, {'url': 'http://securitytracker.com/id?1015477', 'name': '1015477', 'refsource': 'SECTRACK'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-0054', 'STATE': 'PUBLIC', 'ASSIGNER': 'secteam@freebsd.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-0054', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:53:05.979Z', 'dateReserved': '2005-12-30T00:00:00.000Z', 'assignerOrgId': '63664ac6-956c-4cba-a5d0-f46076e16109', 'datePublished': '2006-01-11T21:00:00.000Z', 'assignerShortName': 'freebsd'}, 'dataVersion': '5.1'}
CVE-2005-4780
3.70
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
none
no
partial
2.0.3
2024-04-15 22:23:25.002384+03:00
2025-01-16 23:03:07.838000+03:00
b316b9c784849db8c24ac78551c8a1e2d7394b8ceebba9dff2add330693f9b07
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/15952', 'name': '15952', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23668', 'name': 'lighthousecms-search-xss(23668)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.lighthouse-cms.de/en/news/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/21852', 'name': '21852', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:22.480Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4780', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-15T19:23:25.002384Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T20:03:07.838Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-12-18T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/bid/15952', 'name': '15952', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23668', 'name': 'lighthousecms-search-xss(23668)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.lighthouse-cms.de/en/news/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/21852', 'name': '21852', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology. [It] is an application server ... A technology like this cannot be susceptible to client-side cross-site-scripting-attacks on its own, but only applications created based on such a technology. This does not only apply to Lighthouse, but also to Perl, PHP or web applications based on Java Servlet technology." Since the original researcher is known to test demo pages and is sometimes inaccurate, it is likely that this issue will be REJECTED'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/15952', 'name': '15952', 'refsource': 'BID'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/23668', 'name': 'lighthousecms-search-xss(23668)', 'refsource': 'XF'}, {'url': 'http://www.lighthouse-cms.de/en/news/', 'name': 'http://www.lighthouse-cms.de/en/news/', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/21852', 'name': '21852', 'refsource': 'OSVDB'}, {'url': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'name': 'http://pridels0.blogspot.com/2005/12/lighthouse-cms-xss-vuln.html', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology. [It] is an application server ... A technology like this cannot be susceptible to client-side cross-site-scripting-attacks on its own, but only applications created based on such a technology. This does not only apply to Lighthouse, but also to Perl, PHP or web applications based on Java Servlet technology." Since the original researcher is known to test demo pages and is sometimes inaccurate, it is likely that this issue will be REJECTED.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4780', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4780', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T20:03:59.554Z', 'dateReserved': '2006-04-13T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-04-14T10:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2005-4900
5.90
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
none
no
partial
2.0.3
2026-05-22 19:17:39.588677+03:00
['CWE-327']
2026-05-22 19:16:34.456000+03:00
a0a31fa5aa6097d0d2787dd0d60dbe93db144e7bcf9d7f6919bcfefb125de76f
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://sites.google.com/site/itstheshappening', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/12577', 'name': '12577', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://shattered.io/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://ia.cr/2007/474', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-08T00:01:23.514Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4900', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-22T16:17:39.588677Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-327', 'description': 'CWE-327 Use of a Broken or Risky Cryptographic Algorithm'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-05-22T16:16:34.456Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-02-15T00:00:00.000Z', 'references': [{'url': 'https://sites.google.com/site/itstheshappening', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/bid/12577', 'name': '12577', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://shattered.io/', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'tags': ['x_refsource_MISC']}, {'url': 'http://ia.cr/2007/474', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'tags': ['x_refsource_MISC']}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2020-12-09T08:06:17.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://sites.google.com/site/itstheshappening', 'name': 'https://sites.google.com/site/itstheshappening', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/bid/12577', 'name': '12577', 'refsource': 'BID'}, {'url': 'http://shattered.io/', 'name': 'http://shattered.io/', 'refsource': 'MISC'}, {'url': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'name': 'https://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html', 'refsource': 'MISC'}, {'url': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'name': 'http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1', 'refsource': 'MISC'}, {'url': 'http://ia.cr/2007/474', 'name': 'http://ia.cr/2007/474', 'refsource': 'MISC'}, {'url': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'name': 'https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html', 'refsource': 'MISC'}, {'url': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'name': 'https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.html', 'refsource': 'MISC'}, {'url': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'name': 'https://www.schneier.com/blog/archives/2005/02/sha1_broken.html', 'refsource': 'MISC'}, {'url': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'name': 'https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/', 'refsource': 'MISC'}, {'url': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'name': 'https://kc.mcafee.com/corporate/index?page=content&id=SB10340', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4900', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4900', 'state': 'PUBLISHED', 'dateUpdated': '2026-05-22T16:18:17.909Z', 'dateReserved': '2016-10-14T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2016-10-14T16:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-2005-4349
6.30
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
none
no
partial
2.0.3
2024-04-15 22:20:51.357317+03:00
['CWE-89']
2025-01-16 22:49:31.197000+03:00
6228279a8237507d010143e870612b33df26e11549d5c0f67123db28431e4dbf
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securityreason.com/securityalert/270', 'name': '270', 'tags': ['third-party-advisory', 'x_refsource_SREASON', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2005/2995', 'name': 'ADV-2005-2995', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://marc.info/?l=bugtraq&m=113486637512821&w=2', 'name': '20051217 phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/419829/100/0/threaded', 'name': '20051219 Re: phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18113', 'name': '18113', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/419832/100/0/threaded', 'name': "20051219 about phpMyAdmin's server_privileges.php announced vulnerability", 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T23:38:51.895Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2005-4349', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-15T19:20:51.357317Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-89', 'description': "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:49:31.197Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2005-12-17T05:00:00.000Z', 'references': [{'url': 'http://securityreason.com/securityalert/270', 'name': '270', 'tags': ['third-party-advisory', 'x_refsource_SREASON']}, {'url': 'http://www.vupen.com/english/advisories/2005/2995', 'name': 'ADV-2005-2995', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://marc.info/?l=bugtraq&m=113486637512821&w=2', 'name': '20051217 phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/419829/100/0/threaded', 'name': '20051219 Re: phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/18113', 'name': '18113', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.securityfocus.com/archive/1/419832/100/0/threaded', 'name': "20051219 about phpMyAdmin's server_privileges.php announced vulnerability", 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://securityreason.com/securityalert/270', 'name': '270', 'refsource': 'SREASON'}, {'url': 'http://www.vupen.com/english/advisories/2005/2995', 'name': 'ADV-2005-2995', 'refsource': 'VUPEN'}, {'url': 'http://marc.info/?l=bugtraq&m=113486637512821&w=2', 'name': '20051217 phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/419829/100/0/threaded', 'name': '20051219 Re: phpMyAdmin server_privileges.php SQL Injection Vulnerabilities.', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/18113', 'name': '18113', 'refsource': 'SECUNIA'}, {'url': 'http://www.securityfocus.com/archive/1/419832/100/0/threaded', 'name': "20051219 about phpMyAdmin's server_privileges.php announced vulnerability", 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2005-4349', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2005-4349', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:49:37.380Z', 'dateReserved': '2005-12-19T05:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2005-12-19T16:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-10002
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2026-03-19 20:11:03.634936+03:00
2026-03-19 20:11:22.535000+03:00
254f252a223137f393ba3373b9c44af6f1ba24b771af4fa10825d3662b7d2046
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2026/03/19/1'}, {'url': 'http://www.openwall.com/lists/oss-security/2026/03/22/3'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2026-03-22T23:06:42.361Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-10002', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-03-19T17:11:03.634936Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-03-19T17:11:22.535Z'}}], 'cna': {'title': 'XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes', 'source': {'discovery': 'UNKNOWN'}, 'affected': [{'repo': 'http://github.com/toddr/XML-Parser', 'vendor': 'TODDR', 'product': 'XML::Parser', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '2.45'}], 'packageName': 'XML-Parser', 'programFiles': ['Expat.xs'], 'collectionURL': 'https://cpan.org/modules', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': 'parse_stream'}]}], 'timeline': [{'lang': 'en', 'time': '2006-06-13T00:00:00.000Z', 'value': 'Issue logged in Request Tracker for XML::Parser'}, {'lang': 'en', 'time': '2006-08-11T00:00:00.000Z', 'value': 'Patch provided in Request Tracker for XML::Parser'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Issue migrated to github issue tracker'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Patch provided in github issue tracker'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Included in release 2.46 released to CPAN'}], 'solutions': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13 or upgrade to version 2.46 or later.'}], 'references': [{'url': 'https://rt.cpan.org/Ticket/Display.html?id=19859', 'tags': ['issue-tracking']}, {'url': 'https://github.com/cpan-authors/XML-Parser/issues/64', 'tags': ['issue-tracking']}, {'url': 'https://metacpan.org/release/TODDR/XML-Parser-2.46/changes', 'tags': ['release-notes']}, {'url': 'https://github.com/cpan-authors/XML-Parser/commit/56b0509dfc6b559cd7555ea81ee62e3622069255.patch', 'tags': ['patch']}], 'workarounds': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13.'}], 'x_generator': {'engine': 'cpansec-cna-tool 0.1'}, 'descriptions': [{'lang': 'en', 'value': "XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes.\n\nA :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while SvPV() gives back multi-byte UTF-8 bytes that can exceed the pre-allocated buffer size. This can cause heap corruption (double free or corruption) and crashes."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-122', 'description': 'CWE-122 Heap-based Buffer Overflow'}]}, {'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-176', 'description': 'CWE-176 Improper Handling of Unicode Encoding'}]}], 'providerMetadata': {'orgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'shortName': 'CPANSec', 'dateUpdated': '2026-03-21T11:43:43.607Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-10002', 'state': 'PUBLISHED', 'dateUpdated': '2026-04-29T14:36:41.837Z', 'dateReserved': '2026-03-16T22:47:45.685Z', 'assignerOrgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'datePublished': '2026-03-19T11:03:46.888Z', 'assignerShortName': 'CPANSec'}, 'dataVersion': '5.2'}
CVE-2006-10003
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2026-03-19 20:08:41.621885+03:00
2026-03-19 20:09:53.422000+03:00
595f1f413218318f120e94f480914925f0e69c640db8ac5afec71b6785da83ca
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2026/03/19/2'}, {'url': 'https://lists.debian.org/debian-lts-announce/2026/04/msg00002.html'}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2026-04-04T08:11:42.558Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-10003', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-03-19T17:08:41.621885Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-03-19T17:09:53.422Z'}}], 'cna': {'title': 'XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack', 'source': {'discovery': 'UNKNOWN'}, 'affected': [{'repo': 'http://github.com/toddr/XML-Parser', 'vendor': 'TODDR', 'product': 'XML::Parser', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'custom', 'lessThanOrEqual': '2.47'}], 'packageName': 'XML-Parser', 'programFiles': ['Expat.xs'], 'collectionURL': 'https://cpan.org/modules', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': 'startElement'}]}], 'timeline': [{'lang': 'en', 'time': '2006-06-13T00:00:00.000Z', 'value': 'Issue logged and patch provided in Request Tracker for XML::Parser'}, {'lang': 'en', 'time': '2019-09-23T00:00:00.000Z', 'value': 'Issue migrated to github issue tracker'}, {'lang': 'en', 'time': '2019-09-24T00:00:00.000Z', 'value': 'Patch provided in github issue tracker'}, {'lang': 'en', 'time': '2026-03-16T00:00:00.000Z', 'value': 'PR created and commit merged to git repo'}], 'solutions': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13 or upgrade to version 2.48 or later when it is released.'}], 'references': [{'url': 'https://rt.cpan.org/Ticket/Display.html?id=19860', 'tags': ['issue-tracking']}, {'url': 'https://github.com/cpan-authors/XML-Parser/issues/39', 'tags': ['issue-tracking']}, {'url': 'https://github.com/cpan-authors/XML-Parser/commit/3eb9cc95420fa0c3f76947c4708962546bf27cfd.patch', 'tags': ['patch']}], 'workarounds': [{'lang': 'en', 'value': 'Apply the patch that has been publicly available since 2006-06-13.'}], 'x_generator': {'engine': 'cpansec-cna-tool 0.1'}, 'descriptions': [{'lang': 'en', 'value': 'XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.\n\nIn the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer.\n\nThe bug can be observed when parsing an XML file with very deep element nesting'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-193', 'description': 'CWE-193 Off-by-one Error'}]}, {'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-122', 'description': 'CWE-122 Heap-based Buffer Overflow'}]}], 'providerMetadata': {'orgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'shortName': 'CPANSec', 'dateUpdated': '2026-03-19T11:08:04.341Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-10003', 'state': 'PUBLISHED', 'dateUpdated': '2026-04-04T08:11:42.558Z', 'dateReserved': '2026-03-16T22:52:39.890Z', 'assignerOrgId': '9b29abf9-4ab0-4765-b253-1875cd9b441e', 'datePublished': '2026-03-19T11:08:04.341Z', 'assignerShortName': 'CPANSec'}, 'dataVersion': '5.2'}
CVE-2006-2827
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2025-01-17 16:56:32.615352+03:00
2025-01-17 16:56:14.844000+03:00
9fb69b2771f6ec18c48d216f1e305ce25ccffaa93a13f5301d37a8d1444c4328
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25944', 'name': 'xcart-search-sql-injection(25944)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.osvdb.org/25204', 'name': '25204', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:06:26.640Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-2827', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-17T13:56:32.615352Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T13:56:14.844Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-04-20T00:00:00.000Z', 'references': [{'url': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25944', 'name': 'xcart-search-sql-injection(25944)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.osvdb.org/25204', 'name': '25204', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}], 'descriptions': [{'lang': 'en', 'value': 'SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue in a comment on the original researcher\'s blog, saying "the bug does not impose any security threat and remote attackers can\'t add, modify, or delete information in the back-end database by sending specially-crafted SQL statements to the search.php script using various search parameters." As of 20060605, the original blog entry is unavailable, although ISS also reports the same dispute. CVE has not been able to investigate this issue further, although the researcher sometimes makes inaccurate claims'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T15:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'name': 'http://pridels0.blogspot.com/2006/04/x-cart-sql-inj-vuln.html', 'refsource': 'MISC'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25944', 'name': 'xcart-search-sql-injection(25944)', 'refsource': 'XF'}, {'url': 'http://www.osvdb.org/25204', 'name': '25204', 'refsource': 'OSVDB'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue in a comment on the original researcher\'s blog, saying "the bug does not impose any security threat and remote attackers can\'t add, modify, or delete information in the back-end database by sending specially-crafted SQL statements to the search.php script using various search parameters." As of 20060605, the original blog entry is unavailable, although ISS also reports the same dispute. CVE has not been able to investigate this issue further, although the researcher sometimes makes inaccurate claims.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-2827', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-2827', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T13:56:38.025Z', 'dateReserved': '2006-06-05T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-06-05T17:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-1078
8.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2025-01-16 23:01:08.855744+03:00
2025-01-16 23:00:16.087000+03:00
f6e039d3aa5b4e8c897b55a85651d463812185cd919957ed2de7cd927ee9ef0a
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html', 'name': '20070102 Apache 1.3.37 htpasswd buffer overflow vulnerability', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/426823/100/0/threaded', 'name': '20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://marc.info/?l=thttpd&m=114154083000296&w=2', 'name': '[thttpd] 20060305 Re: htpasswd.c security issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://seclists.org/bugtraq/2004/Oct/0359.html', 'name': '20041029 Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/16972', 'name': '16972', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=41279', 'tags': ['x_transferred']}, {'url': 'http://marc.info/?l=thttpd&m=114153031201867&w=2', 'name': '[thttpd] 20060305 htpasswd.c security issues', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25216', 'name': 'thttpd-command-file-bo(25216)', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html', 'name': '20040916 FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory.', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=31975', 'tags': ['x_transferred']}, {'url': 'http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html', 'name': '20041029 Apache 1.3.33 local buffer overflow in apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/31236', 'name': 'apache-htpasswd-strcpy-bo(31236)', 'tags': ['vdb-entry', 'x_transferred']}, {'url': 'http://seclists.org/fulldisclosure/2023/Nov/13', 'name': '20231127 SEC Consult SA-20231122 :: Multiple Vulnerabilities in m-privacy TightGate-Pro', 'tags': ['mailing-list', 'x_transferred']}, {'url': 'http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:56:15.560Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-1078', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-16T20:01:08.855744Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T20:00:16.087Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-03-05T00:00:00.000Z', 'references': [{'url': 'http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html', 'name': '20070102 Apache 1.3.37 htpasswd buffer overflow vulnerability', 'tags': ['mailing-list']}, {'url': 'http://www.securityfocus.com/archive/1/426823/100/0/threaded', 'name': '20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.', 'tags': ['mailing-list']}, {'url': 'http://marc.info/?l=thttpd&m=114154083000296&w=2', 'name': '[thttpd] 20060305 Re: htpasswd.c security issues', 'tags': ['mailing-list']}, {'url': 'http://seclists.org/bugtraq/2004/Oct/0359.html', 'name': '20041029 Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list']}, {'url': 'http://www.securityfocus.com/bid/16972', 'name': '16972', 'tags': ['vdb-entry']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=41279'}, {'url': 'http://marc.info/?l=thttpd&m=114153031201867&w=2', 'name': '[thttpd] 20060305 htpasswd.c security issues', 'tags': ['mailing-list']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25216', 'name': 'thttpd-command-file-bo(25216)', 'tags': ['vdb-entry']}, {'url': 'http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html', 'name': '20040916 FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory.', 'tags': ['mailing-list']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=31975'}, {'url': 'http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html', 'name': '20041029 Apache 1.3.33 local buffer overflow in apache 1.3.31 not fixed in .33?', 'tags': ['mailing-list']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/31236', 'name': 'apache-htpasswd-strcpy-bo(31236)', 'tags': ['vdb-entry']}, {'url': 'http://seclists.org/fulldisclosure/2023/Nov/13', 'name': '20231127 SEC Consult SA-20231122 :: Multiple Vulnerabilities in m-privacy TightGate-Pro', 'tags': ['mailing-list']}, {'url': 'http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-Execution-Insecure-Permissions.html'}], 'descriptions': [{'lang': 'en', 'value': 'Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2023-11-28T17:06:25.293Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-1078', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T20:02:13.764Z', 'dateReserved': '2006-03-08T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-03-09T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-2362
7.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
partial
2.0.3
2025-01-16 23:05:43.320995+03:00
['CWE-787']
2025-01-16 23:04:43.491000+03:00
35ad6f0dcd716176d06966264a0c6d37444f33eff4c25940165e2d5577070d74
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://secunia.com/advisories/20188', 'name': '20188', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20550', 'name': '20550', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/22932', 'name': '22932', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://secunia.com/advisories/27441', 'name': '27441', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.trustix.org/errata/2006/0034/', 'name': '2006-0034', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/17950', 'name': '17950', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.html', 'name': '[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.', 'tags': ['mailing-list', 'x_refsource_MLIST', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2007/3665', 'name': 'ADV-2007-3665', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.novell.com/linux/security/advisories/2006_26_sr.html', 'name': 'SUSE-SR:2006:026', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/1924', 'name': 'ADV-2006-1924', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.securitytracker.com/id?1018872', 'name': '1018872', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20531', 'name': '20531', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.ubuntu.com/usn/usn-292-1', 'name': 'USN-292-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU', 'x_transferred']}, {'url': 'http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html', 'name': 'APPLE-SA-2007-10-30', 'tags': ['vendor-advisory', 'x_refsource_APPLE', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26644', 'name': 'binutils-libbfd-bo(26644)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T17:51:04.067Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-2362', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-16T20:05:43.320995Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-787', 'description': 'CWE-787 Out-of-bounds Write'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T20:04:43.491Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-04-18T04:00:00.000Z', 'references': [{'url': 'http://secunia.com/advisories/20188', 'name': '20188', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/20550', 'name': '20550', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/22932', 'name': '22932', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://secunia.com/advisories/27441', 'name': '27441', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.trustix.org/errata/2006/0034/', 'name': '2006-0034', 'tags': ['vendor-advisory', 'x_refsource_TRUSTIX']}, {'url': 'http://www.securityfocus.com/bid/17950', 'name': '17950', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.html', 'name': '[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.', 'tags': ['mailing-list', 'x_refsource_MLIST']}, {'url': 'http://www.vupen.com/english/advisories/2007/3665', 'name': 'ADV-2007-3665', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.novell.com/linux/security/advisories/2006_26_sr.html', 'name': 'SUSE-SR:2006:026', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://www.vupen.com/english/advisories/2006/1924', 'name': 'ADV-2006-1924', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.securitytracker.com/id?1018872', 'name': '1018872', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://secunia.com/advisories/20531', 'name': '20531', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.ubuntu.com/usn/usn-292-1', 'name': 'USN-292-1', 'tags': ['vendor-advisory', 'x_refsource_UBUNTU']}, {'url': 'http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html', 'name': 'APPLE-SA-2007-10-30', 'tags': ['vendor-advisory', 'x_refsource_APPLE']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26644', 'name': 'binutils-libbfd-bo(26644)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2017-07-19T19:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://secunia.com/advisories/20188', 'name': '20188', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/20550', 'name': '20550', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/22932', 'name': '22932', 'refsource': 'SECUNIA'}, {'url': 'http://secunia.com/advisories/27441', 'name': '27441', 'refsource': 'SECUNIA'}, {'url': 'http://www.trustix.org/errata/2006/0034/', 'name': '2006-0034', 'refsource': 'TRUSTIX'}, {'url': 'http://www.securityfocus.com/bid/17950', 'name': '17950', 'refsource': 'BID'}, {'url': 'http://www.mail-archive.com/bug-binutils@gnu.org/msg01516.html', 'name': '[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.', 'refsource': 'MLIST'}, {'url': 'http://www.vupen.com/english/advisories/2007/3665', 'name': 'ADV-2007-3665', 'refsource': 'VUPEN'}, {'url': 'http://www.novell.com/linux/security/advisories/2006_26_sr.html', 'name': 'SUSE-SR:2006:026', 'refsource': 'SUSE'}, {'url': 'http://www.vupen.com/english/advisories/2006/1924', 'name': 'ADV-2006-1924', 'refsource': 'VUPEN'}, {'url': 'http://www.securitytracker.com/id?1018872', 'name': '1018872', 'refsource': 'SECTRACK'}, {'url': 'http://secunia.com/advisories/20531', 'name': '20531', 'refsource': 'SECUNIA'}, {'url': 'http://www.ubuntu.com/usn/usn-292-1', 'name': 'USN-292-1', 'refsource': 'UBUNTU'}, {'url': 'http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html', 'name': 'APPLE-SA-2007-10-30', 'refsource': 'APPLE'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26644', 'name': 'binutils-libbfd-bo(26644)', 'refsource': 'XF'}, {'url': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'name': 'http://sourceware.org/bugzilla/show_bug.cgi?id=2584', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-2362', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-2362', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T20:05:47.171Z', 'dateReserved': '2006-05-15T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-05-15T20:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-2492
8.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
active
no
total
2.0.3
2025-02-07 16:11:21.653549+03:00
['CWE-120']
2025-02-07 16:11:28.960000+03:00
4296a0baf3f3c1196f26ccdb5b1523e4f47fef14c7777ce0e0dc1b2e698fd219
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027', 'name': 'MS06-027', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068', 'name': 'oval:org.mitre.oval:def:2068', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://isc.sans.org/diary.php?storyid=1345', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.osvdb.org/25635', 'name': '25635', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738', 'name': 'oval:org.mitre.oval:def:1738', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://isc.sans.org/diary.php?storyid=1346', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-164A.html', 'name': 'TA06-164A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/1872', 'name': 'ADV-2006-1872', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/18037', 'name': '18037', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20153', 'name': '20153', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26556', 'name': 'word-code-execution(26556)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/446012', 'name': 'VU#446012', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1016130', 'name': '1016130', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418', 'name': 'oval:org.mitre.oval:def:1418', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-139A.html', 'name': 'TA06-139A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'tags': ['x_refsource_MISC', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T17:51:04.545Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-2492', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-02-07T13:11:21.653549Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-06-08', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-2492'}}}], 'timeline': [{'lang': 'en', 'time': '2022-06-08T00:00:00.000Z', 'value': 'CVE-2006-2492 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-2492', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-120', 'description': "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T13:11:28.960Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-05-19T00:00:00.000Z', 'references': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027', 'name': 'MS06-027', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068', 'name': 'oval:org.mitre.oval:def:2068', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://isc.sans.org/diary.php?storyid=1345', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.osvdb.org/25635', 'name': '25635', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'tags': ['x_refsource_CONFIRM']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738', 'name': 'oval:org.mitre.oval:def:1738', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://isc.sans.org/diary.php?storyid=1346', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-164A.html', 'name': 'TA06-164A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.vupen.com/english/advisories/2006/1872', 'name': 'ADV-2006-1872', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.securityfocus.com/bid/18037', 'name': '18037', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/20153', 'name': '20153', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26556', 'name': 'word-code-execution(26556)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.kb.cert.org/vuls/id/446012', 'name': 'VU#446012', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://securitytracker.com/id?1016130', 'name': '1016130', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418', 'name': 'oval:org.mitre.oval:def:1418', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-139A.html', 'name': 'TA06-139A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'tags': ['x_refsource_MISC']}], 'descriptions': [{'lang': 'en', 'value': 'Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '37e5125f-f79b-445b-8fad-9564f167944b', 'shortName': 'certcc', 'dateUpdated': '2018-10-12T19:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027', 'name': 'MS06-027', 'refsource': 'MS'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068', 'name': 'oval:org.mitre.oval:def:2068', 'refsource': 'OVAL'}, {'url': 'http://isc.sans.org/diary.php?storyid=1345', 'name': 'http://isc.sans.org/diary.php?storyid=1345', 'refsource': 'MISC'}, {'url': 'http://www.osvdb.org/25635', 'name': '25635', 'refsource': 'OSVDB'}, {'url': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'name': 'http://www.microsoft.com/technet/security/advisory/919637.mspx', 'refsource': 'CONFIRM'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738', 'name': 'oval:org.mitre.oval:def:1738', 'refsource': 'OVAL'}, {'url': 'http://isc.sans.org/diary.php?storyid=1346', 'name': 'http://isc.sans.org/diary.php?storyid=1346', 'refsource': 'MISC'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-164A.html', 'name': 'TA06-164A', 'refsource': 'CERT'}, {'url': 'http://www.vupen.com/english/advisories/2006/1872', 'name': 'ADV-2006-1872', 'refsource': 'VUPEN'}, {'url': 'http://www.securityfocus.com/bid/18037', 'name': '18037', 'refsource': 'BID'}, {'url': 'http://secunia.com/advisories/20153', 'name': '20153', 'refsource': 'SECUNIA'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/26556', 'name': 'word-code-execution(26556)', 'refsource': 'XF'}, {'url': 'http://www.kb.cert.org/vuls/id/446012', 'name': 'VU#446012', 'refsource': 'CERT-VN'}, {'url': 'http://securitytracker.com/id?1016130', 'name': '1016130', 'refsource': 'SECTRACK'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418', 'name': 'oval:org.mitre.oval:def:1418', 'refsource': 'OVAL'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-139A.html', 'name': 'TA06-139A', 'refsource': 'CERT'}, {'url': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'name': 'http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx', 'refsource': 'MISC'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-2492', 'STATE': 'PUBLIC', 'ASSIGNER': 'cert@cert.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-2492', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:56.729Z', 'dateReserved': '2006-05-19T00:00:00.000Z', 'assignerOrgId': '37e5125f-f79b-445b-8fad-9564f167944b', 'datePublished': '2006-05-20T00:00:00.000Z', 'assignerShortName': 'certcc'}, 'dataVersion': '5.1'}
CVE-2006-20001
none
no
partial
2.0.3
2024-08-01 18:32:06.669346+03:00
2024-08-01 18:32:24.196000+03:00
08183700adc30198ac37f78e6a5bf61878e7fcd5b781210eacd4e849ed183e19
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'https://security.netapp.com/advisory/ntap-20230316-0005/'}, {'url': 'https://httpd.apache.org/security/vulnerabilities_24.html', 'tags': ['vendor-advisory', 'x_transferred']}, {'url': 'https://security.gentoo.org/glsa/202309-01', 'tags': ['x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T20:57:41.059Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-20001', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-08-01T15:32:06.669346Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-08-01T15:32:24.196Z'}}], 'cna': {'title': 'Apache HTTP Server: mod_dav out of bounds read, or write of zero byte', 'source': {'discovery': 'UNKNOWN'}, 'metrics': [{'other': {'type': 'Textual description of severity', 'content': {'text': 'moderate'}}}], 'affected': [{'vendor': 'Apache Software Foundation', 'product': 'Apache HTTP Server', 'versions': [{'status': 'affected', 'version': '2.4', 'versionType': 'semver', 'lessThanOrEqual': '2.4.54'}], 'defaultStatus': 'unaffected'}], 'timeline': [{'lang': 'en', 'time': '2006-10-31T09:00:00.000Z', 'value': 'Described in first edition of "The Art of Software Security Assessment"'}, {'lang': 'en', 'time': '2022-08-10T12:00:00.000Z', 'value': 'Reported to security team'}], 'references': [{'url': 'https://httpd.apache.org/security/vulnerabilities_24.html', 'tags': ['vendor-advisory']}, {'url': 'https://security.gentoo.org/glsa/202309-01'}], 'x_generator': {'engine': 'Vulnogram 0.1.0-dev'}, 'descriptions': [{'lang': 'en', 'value': 'A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.\n\nThis issue affects Apache HTTP Server 2.4.54 and earlier.', 'supportingMedia': [{'type': 'text/html', 'value': 'A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.<br><br>This issue affects Apache HTTP Server 2.4.54 and earlier.<br>', 'base64': False}]}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-787', 'description': 'CWE-787 Out-of-bounds Write'}]}], 'providerMetadata': {'orgId': 'f0158376-9dc2-43b6-827c-5f631a4d8d09', 'shortName': 'apache', 'dateUpdated': '2023-09-08T21:06:27.122Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-20001', 'state': 'PUBLISHED', 'dateUpdated': '2025-02-13T16:27:07.996Z', 'dateReserved': '2022-09-01T14:24:05.065Z', 'assignerOrgId': 'f0158376-9dc2-43b6-827c-5f631a4d8d09', 'datePublished': '2023-01-17T19:07:27.136Z', 'assignerShortName': 'apache'}, 'dataVersion': '5.1'}
CVE-2006-1547
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
active
yes
partial
2.0.3
2025-02-07 16:35:54.338056+03:00
['CWE-749']
2025-02-07 16:26:17.027000+03:00
bc09e5a272e64cb6d858197a00bf03e332753584eaa47421f6e3ac8045ba250a
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securitytracker.com/id?1015856', 'name': '1015856', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/1205', 'name': 'ADV-2006-1205', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/17342', 'name': '17342', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://secunia.com/advisories/19493', 'name': '19493', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25613', 'name': 'struts-actionform-dos(25613)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html', 'name': 'SUSE-SR:2006:010', 'tags': ['vendor-advisory', 'x_refsource_SUSE', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20117', 'name': '20117', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=38534', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T17:19:48.247Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-1547', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'active'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-02-07T13:35:54.338056Z'}}}, {'other': {'type': 'kev', 'content': {'dateAdded': '2022-01-21', 'reference': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-1547'}}}], 'timeline': [{'lang': 'en', 'time': '2022-01-21T00:00:00.000Z', 'value': 'CVE-2006-1547 added to CISA KEV'}], 'references': [{'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-1547', 'tags': ['government-resource']}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-749', 'description': 'CWE-749 Exposed Dangerous Method or Function'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-02-07T13:26:17.027Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-03-30T00:00:00.000Z', 'references': [{'url': 'http://securitytracker.com/id?1015856', 'name': '1015856', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.vupen.com/english/advisories/2006/1205', 'name': 'ADV-2006-1205', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.securityfocus.com/bid/17342', 'name': '17342', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://secunia.com/advisories/19493', 'name': '19493', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/25613', 'name': 'struts-actionform-dos(25613)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html', 'name': 'SUSE-SR:2006:010', 'tags': ['vendor-advisory', 'x_refsource_SUSE']}, {'url': 'http://secunia.com/advisories/20117', 'name': '20117', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://issues.apache.org/bugzilla/show_bug.cgi?id=38534', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'shortName': 'redhat', 'dateUpdated': '2017-07-19T15:57:01.000Z'}}}, 'cveMetadata': {'cveId': 'CVE-2006-1547', 'state': 'PUBLISHED', 'dateUpdated': '2025-10-22T00:05:56.875Z', 'dateReserved': '2006-03-30T00:00:00.000Z', 'assignerOrgId': '53f830b8-0a3f-465b-8143-3b8a9948e749', 'datePublished': '2006-03-30T22:00:00.000Z', 'assignerShortName': 'redhat'}, 'dataVersion': '5.1'}
CVE-2006-3547
5.50
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
none
no
partial
2.0.3
2024-04-15 21:27:47.510692+03:00
2025-01-17 16:58:34.915000+03:00
062886d21054b6f81a48d08fb911cf05bbeee65e3a558d9b6f5065e455365107
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/437806/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437809/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/27524', 'name': '27524', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437756/100/200/threaded', 'name': '20060618 Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:30:34.372Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-3547', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-04-15T18:27:47.510692Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T13:58:34.915Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-06-18T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/437806/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/437809/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/27524', 'name': '27524', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/437756/100/200/threaded', 'name': '20060618 Vm ware 0day dos exploit by n00b.', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-18T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/437806/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/437809/100/200/threaded', 'name': '20060620 Re: Vm ware 0day dos exploit by n00b.', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/27524', 'name': '27524', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/437756/100/200/threaded', 'name': '20060618 Vm ware 0day dos exploit by n00b.', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-3547', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-3547', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T13:58:42.936Z', 'dateReserved': '2006-07-12T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-07-13T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-3136
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2024-04-15 21:14:06.571615+03:00
['CWE-94']
2025-01-17 16:57:28.939000+03:00
e3d6c3d7c1535156657bb66bed9ed66b8b74bcad4cd5cbddf91c6781f3b594eb
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/27502', 'name': '27502', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437986/100/200/threaded', 'name': '20060617 Re: file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://securityreason.com/securityalert/1120', 'name': '1120', 'tags': ['third-party-advisory', 'x_refsource_SREASON', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/2408', 'name': 'ADV-2006-2408', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1016325', 'name': '1016325', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/437423/100/0/threaded', 'name': '20060616 file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/18475', 'name': '18475', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:16:05.875Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-3136', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-04-15T18:14:06.571615Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T13:57:28.939Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-06-16T04:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/27502', 'name': '27502', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/437986/100/200/threaded', 'name': '20060617 Re: file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://securityreason.com/securityalert/1120', 'name': '1120', 'tags': ['third-party-advisory', 'x_refsource_SREASON']}, {'url': 'http://www.vupen.com/english/advisories/2006/2408', 'name': 'ADV-2006-2408', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://securitytracker.com/id?1016325', 'name': '1016325', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.securityfocus.com/archive/1/437423/100/0/threaded', 'name': '20060616 file include exploits in nucleus 3.23', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/bid/18475', 'name': '18475', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-18T18:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/27502', 'name': '27502', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/437986/100/200/threaded', 'name': '20060617 Re: file include exploits in nucleus 3.23', 'refsource': 'BUGTRAQ'}, {'url': 'http://securityreason.com/securityalert/1120', 'name': '1120', 'refsource': 'SREASON'}, {'url': 'http://www.vupen.com/english/advisories/2006/2408', 'name': 'ADV-2006-2408', 'refsource': 'VUPEN'}, {'url': 'http://securitytracker.com/id?1016325', 'name': '1016325', 'refsource': 'SECTRACK'}, {'url': 'http://www.securityfocus.com/archive/1/437423/100/0/threaded', 'name': '20060616 file include exploits in nucleus 3.23', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/bid/18475', 'name': '18475', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-3136', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-3136', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T13:57:51.051Z', 'dateReserved': '2006-06-22T04:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-06-23T02:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-0755
5.60
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
none
yes
total
2.0.3
2024-04-15 21:06:59.724935+03:00
2025-01-16 22:57:32.174000+03:00
7ffc8c1a7e4340d4c7a612fa23f3732b33ff5efe388685de41c6d03135ab129c
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/424957/100/0/threaded', 'name': '20060214 dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/23210', 'name': '23210', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23216', 'name': '23216', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23217', 'name': '23217', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://secunia.com/advisories/18879', 'name': '18879', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://www.osvdb.org/23209', 'name': '23209', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/16648', 'name': '16648', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.osvdb.org/23212', 'name': '23212', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23215', 'name': '23215', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24738', 'name': 'dotproject-multiple-basedir-file-include(24738)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.osvdb.org/23213', 'name': '23213', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/0604', 'name': 'ADV-2006-0604', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://www.osvdb.org/23214', 'name': '23214', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23218', 'name': '23218', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23211', 'name': '23211', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.osvdb.org/23219', 'name': '23219', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/425285/100/0/threaded', 'name': '20060215 Re: dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T16:48:56.618Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.6, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-0755', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2024-04-15T18:06:59.724935Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-16T19:57:32.174Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-02-14T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/424957/100/0/threaded', 'name': '20060214 dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/23210', 'name': '23210', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23216', 'name': '23216', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23217', 'name': '23217', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://secunia.com/advisories/18879', 'name': '18879', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://www.osvdb.org/23209', 'name': '23209', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/16648', 'name': '16648', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.osvdb.org/23212', 'name': '23212', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23215', 'name': '23215', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24738', 'name': 'dotproject-multiple-basedir-file-include(24738)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.osvdb.org/23213', 'name': '23213', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.vupen.com/english/advisories/2006/0604', 'name': 'ADV-2006-0604', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://www.osvdb.org/23214', 'name': '23214', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23218', 'name': '23218', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23211', 'name': '23211', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.osvdb.org/23219', 'name': '23219', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/425285/100/0/threaded', 'name': '20060215 Re: dotproject <= 2.0.1 remote code execution', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-19T14:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/424957/100/0/threaded', 'name': '20060214 dotproject <= 2.0.1 remote code execution', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/23210', 'name': '23210', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23216', 'name': '23216', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23217', 'name': '23217', 'refsource': 'OSVDB'}, {'url': 'http://secunia.com/advisories/18879', 'name': '18879', 'refsource': 'SECUNIA'}, {'url': 'http://www.osvdb.org/23209', 'name': '23209', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/16648', 'name': '16648', 'refsource': 'BID'}, {'url': 'http://www.osvdb.org/23212', 'name': '23212', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23215', 'name': '23215', 'refsource': 'OSVDB'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/24738', 'name': 'dotproject-multiple-basedir-file-include(24738)', 'refsource': 'XF'}, {'url': 'http://www.osvdb.org/23213', 'name': '23213', 'refsource': 'OSVDB'}, {'url': 'http://www.vupen.com/english/advisories/2006/0604', 'name': 'ADV-2006-0604', 'refsource': 'VUPEN'}, {'url': 'http://www.osvdb.org/23214', 'name': '23214', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23218', 'name': '23218', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23211', 'name': '23211', 'refsource': 'OSVDB'}, {'url': 'http://www.osvdb.org/23219', 'name': '23219', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/425285/100/0/threaded', 'name': '20060215 Re: dotproject <= 2.0.1 remote code execution', 'refsource': 'BUGTRAQ'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-0755', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-0755', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-16T19:58:25.845Z', 'dateReserved': '2006-02-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-02-18T02:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-3730
8.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
poc
no
total
2.0.3
2026-02-25 20:54:05.428144+03:00
['CWE-94']
['https://www.exploit-db.com/exploits/2440']
2026-01-12 17:44:32.572000+03:00
6ce5e63e25aeb9c48e51d0032467e426b93f95833b75af54160d25841452a657
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://securitytracker.com/id?1016941', 'name': '1016941', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-283A.html', 'name': 'TA06-283A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-270A.html', 'name': 'TA06-270A', 'tags': ['third-party-advisory', 'x_refsource_CERT', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-057', 'name': 'MS06-057', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/753044', 'name': 'VU#753044', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447174/100/0/threaded', 'name': '20060927 Exploit module available for WebViewFolderIcon setSlice 0-day', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A339', 'name': 'oval:org.mitre.oval:def:339', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://isc.sans.org/diary.php?storyid=1742', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/27804', 'name': 'ie-webviewfoldericon-dos(27804)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447383/100/100/threaded', 'name': '20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447426/100/0/threaded', 'name': '20060930 setSlice exploited in the wild - massively', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://riosec.com/msie-setslice-vuln', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.osvdb.org/27110', 'name': '27110', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/19030', 'name': '19030', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/2882', 'name': 'ADV-2006-2882', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'https://www.exploit-db.com/exploits/2440', 'name': '2440', 'tags': ['exploit', 'x_refsource_EXPLOIT-DB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/447490/100/0/threaded', 'name': '20060930 ZERT patch for setSlice()', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/22159', 'name': '22159', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T18:39:54.001Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-3730', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'poc'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-02-25T17:54:05.428144Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2026-01-12T14:44:32.572Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-07-18T00:00:00.000Z', 'references': [{'url': 'http://securitytracker.com/id?1016941', 'name': '1016941', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-283A.html', 'name': 'TA06-283A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-270A.html', 'name': 'TA06-270A', 'tags': ['third-party-advisory', 'x_refsource_CERT']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-057', 'name': 'MS06-057', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.kb.cert.org/vuls/id/753044', 'name': 'VU#753044', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.securityfocus.com/archive/1/447174/100/0/threaded', 'name': '20060927 Exploit module available for WebViewFolderIcon setSlice 0-day', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A339', 'name': 'oval:org.mitre.oval:def:339', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://isc.sans.org/diary.php?storyid=1742', 'tags': ['x_refsource_MISC']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/27804', 'name': 'ie-webviewfoldericon-dos(27804)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/archive/1/447383/100/100/threaded', 'name': '20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.securityfocus.com/archive/1/447426/100/0/threaded', 'name': '20060930 setSlice exploited in the wild - massively', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://riosec.com/msie-setslice-vuln', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.osvdb.org/27110', 'name': '27110', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/bid/19030', 'name': '19030', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://www.vupen.com/english/advisories/2006/2882', 'name': 'ADV-2006-2882', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'tags': ['x_refsource_MISC']}, {'url': 'https://www.exploit-db.com/exploits/2440', 'name': '2440', 'tags': ['exploit', 'x_refsource_EXPLOIT-DB']}, {'url': 'http://www.securityfocus.com/archive/1/447490/100/0/threaded', 'name': '20060930 ZERT patch for setSlice()', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/22159', 'name': '22159', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}], 'descriptions': [{'lang': 'en', 'value': 'Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-17T20:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://securitytracker.com/id?1016941', 'name': '1016941', 'refsource': 'SECTRACK'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-283A.html', 'name': 'TA06-283A', 'refsource': 'CERT'}, {'url': 'http://www.us-cert.gov/cas/techalerts/TA06-270A.html', 'name': 'TA06-270A', 'refsource': 'CERT'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-057', 'name': 'MS06-057', 'refsource': 'MS'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'refsource': 'HP'}, {'url': 'http://www.kb.cert.org/vuls/id/753044', 'name': 'VU#753044', 'refsource': 'CERT-VN'}, {'url': 'http://www.securityfocus.com/archive/1/447174/100/0/threaded', 'name': '20060927 Exploit module available for WebViewFolderIcon setSlice 0-day', 'refsource': 'BUGTRAQ'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A339', 'name': 'oval:org.mitre.oval:def:339', 'refsource': 'OVAL'}, {'url': 'http://isc.sans.org/diary.php?storyid=1742', 'name': 'http://isc.sans.org/diary.php?storyid=1742', 'refsource': 'MISC'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/27804', 'name': 'ie-webviewfoldericon-dos(27804)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/archive/1/447383/100/100/threaded', 'name': '20060929 Determina zero-day fix for CVE-2006-3730 (WebViewFolderIcon setSlice Integer Overflow)', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.securityfocus.com/archive/1/447426/100/0/threaded', 'name': '20060930 setSlice exploited in the wild - massively', 'refsource': 'BUGTRAQ'}, {'url': 'http://riosec.com/msie-setslice-vuln', 'name': 'http://riosec.com/msie-setslice-vuln', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'refsource': 'HP'}, {'url': 'http://www.osvdb.org/27110', 'name': '27110', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/bid/19030', 'name': '19030', 'refsource': 'BID'}, {'url': 'http://www.vupen.com/english/advisories/2006/2882', 'name': 'ADV-2006-2882', 'refsource': 'VUPEN'}, {'url': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'name': 'http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html', 'refsource': 'MISC'}, {'url': 'https://www.exploit-db.com/exploits/2440', 'name': '2440', 'refsource': 'EXPLOIT-DB'}, {'url': 'http://www.securityfocus.com/archive/1/447490/100/0/threaded', 'name': '20060930 ZERT patch for setSlice()', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/22159', 'name': '22159', 'refsource': 'SECUNIA'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-3730', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-3730', 'state': 'PUBLISHED', 'dateUpdated': '2026-02-25T17:54:35.799Z', 'dateReserved': '2006-07-19T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-07-19T23:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.2'}
CVE-2006-5393
5.50
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
none
no
partial
2.0.3
2025-04-03 18:40:54.413762+03:00
['CWE-125']
2025-04-03 18:41:47.270000+03:00
2ba70b128216429a56cf97c109bc9c6717d0ca6c08be188b9b0194d9a2560de0
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml', 'name': '20061009 Limitations in Cisco Secure Desktop', 'tags': ['vendor-advisory', 'x_refsource_CISCO', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/20410', 'name': '20410', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1017018', 'name': '1017018', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:48:30.336Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5393', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:40:54.413762Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-125', 'description': 'CWE-125 Out-of-bounds Read'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:41:47.270Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-10-09T00:00:00.000Z', 'references': [{'url': 'http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml', 'name': '20061009 Limitations in Cisco Secure Desktop', 'tags': ['vendor-advisory', 'x_refsource_CISCO']}, {'url': 'http://www.securityfocus.com/bid/20410', 'name': '20410', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'http://securitytracker.com/id?1017018', 'name': '1017018', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}], 'descriptions': [{'lang': 'en', 'value': "Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session."}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-11-08T10:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml', 'name': '20061009 Limitations in Cisco Secure Desktop', 'refsource': 'CISCO'}, {'url': 'http://www.securityfocus.com/bid/20410', 'name': '20410', 'refsource': 'BID'}, {'url': 'http://securitytracker.com/id?1017018', 'name': '1017018', 'refsource': 'SECTRACK'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': "Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session."}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5393', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5393', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:41:56.776Z', 'dateReserved': '2006-10-18T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-10-18T19:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-5708
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
none
yes
partial
2.0.3
2025-04-03 18:25:25.541724+03:00
['CWE-400']
2025-04-03 18:25:07.817000+03:00
10febbc3d7072ab544addf6decc9792c7a22d6dc7ac17f99bb6d4ee844608cb2
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T20:04:54.460Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5708', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:25:25.541724Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-400', 'description': 'CWE-400 Uncontrolled Resource Consumption'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:25:07.817Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'tags': ['x_refsource_CONFIRM']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-11-04T01:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'name': 'http://files.altn.com/MDaemon/Release/RelNotes_en.txt', 'refsource': 'CONFIRM'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5708', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5708', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:26:14.870Z', 'dateReserved': '2006-11-03T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-11-04T01:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-4692
none
no
partial
2.0.3
2024-10-15 17:15:25.340433+03:00
2024-10-15 17:16:27.152000+03:00
797b2c741e51964c3a508b4cea683ecb69007907f2ec819fc75c129b70e15d76
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.osvdb.org/29424', 'name': '29424', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.kb.cert.org/vuls/id/703936', 'name': 'VU#703936', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/20318', 'name': '20318', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-065', 'name': 'MS06-065', 'tags': ['vendor-advisory', 'x_refsource_MS', 'x_transferred']}, {'url': 'http://www.vupen.com/english/advisories/2006/3984', 'name': 'ADV-2006-3984', 'tags': ['vdb-entry', 'x_refsource_VUPEN', 'x_transferred']}, {'url': 'http://secunia.com/secunia_research/2006-54/advisory/', 'tags': ['x_refsource_MISC', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/448696/100/0/threaded', 'name': '20061014 Re: Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://secunia.com/advisories/20717', 'name': '20717', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496', 'name': 'oval:org.mitre.oval:def:496', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/448273/100/0/threaded', 'name': '20061011 Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1017037', 'name': '1017037', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:23:40.860Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-4692', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'partial'}], 'version': '2.0.3', 'timestamp': '2024-10-15T14:15:25.340433Z'}}}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2024-10-15T14:16:27.152Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-10-10T04:00:00.000Z', 'references': [{'url': 'http://www.osvdb.org/29424', 'name': '29424', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.kb.cert.org/vuls/id/703936', 'name': 'VU#703936', 'tags': ['third-party-advisory', 'x_refsource_CERT-VN']}, {'url': 'http://www.securityfocus.com/bid/20318', 'name': '20318', 'tags': ['vdb-entry', 'x_refsource_BID']}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-065', 'name': 'MS06-065', 'tags': ['vendor-advisory', 'x_refsource_MS']}, {'url': 'http://www.vupen.com/english/advisories/2006/3984', 'name': 'ADV-2006-3984', 'tags': ['vdb-entry', 'x_refsource_VUPEN']}, {'url': 'http://secunia.com/secunia_research/2006-54/advisory/', 'tags': ['x_refsource_MISC']}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'tags': ['vendor-advisory', 'x_refsource_HP']}, {'url': 'http://www.securityfocus.com/archive/1/448696/100/0/threaded', 'name': '20061014 Re: Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://secunia.com/advisories/20717', 'name': '20717', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496', 'name': 'oval:org.mitre.oval:def:496', 'tags': ['vdb-entry', 'signature', 'x_refsource_OVAL']}, {'url': 'http://www.securityfocus.com/archive/1/448273/100/0/threaded', 'name': '20061011 Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://securitytracker.com/id?1017037', 'name': '1017037', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}], 'descriptions': [{'lang': 'en', 'value': 'Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': 'f38d906d-7342-40ea-92c1-6c4a2c6478c8', 'shortName': 'microsoft', 'dateUpdated': '2018-10-18T00:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.osvdb.org/29424', 'name': '29424', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'SSRT061264', 'refsource': 'HP'}, {'url': 'http://www.kb.cert.org/vuls/id/703936', 'name': 'VU#703936', 'refsource': 'CERT-VN'}, {'url': 'http://www.securityfocus.com/bid/20318', 'name': '20318', 'refsource': 'BID'}, {'url': 'https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-065', 'name': 'MS06-065', 'refsource': 'MS'}, {'url': 'http://www.vupen.com/english/advisories/2006/3984', 'name': 'ADV-2006-3984', 'refsource': 'VUPEN'}, {'url': 'http://secunia.com/secunia_research/2006-54/advisory/', 'name': 'http://secunia.com/secunia_research/2006-54/advisory/', 'refsource': 'MISC'}, {'url': 'http://www.securityfocus.com/archive/1/449179/100/0/threaded', 'name': 'HPSBST02161', 'refsource': 'HP'}, {'url': 'http://www.securityfocus.com/archive/1/448696/100/0/threaded', 'name': '20061014 Re: Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'refsource': 'BUGTRAQ'}, {'url': 'http://secunia.com/advisories/20717', 'name': '20717', 'refsource': 'SECUNIA'}, {'url': 'https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496', 'name': 'oval:org.mitre.oval:def:496', 'refsource': 'OVAL'}, {'url': 'http://www.securityfocus.com/archive/1/448273/100/0/threaded', 'name': '20061011 Secunia Research: Microsoft Windows Object Packager Dialog Spoofing', 'refsource': 'BUGTRAQ'}, {'url': 'http://securitytracker.com/id?1017037', 'name': '1017037', 'refsource': 'SECTRACK'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-4692', 'STATE': 'PUBLIC', 'ASSIGNER': 'secure@microsoft.com'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-4692', 'state': 'PUBLISHED', 'dateUpdated': '2024-10-15T14:16:30.576Z', 'dateReserved': '2006-09-11T04:00:00.000Z', 'assignerOrgId': 'f38d906d-7342-40ea-92c1-6c4a2c6478c8', 'datePublished': '2006-10-11T02:00:00.000Z', 'assignerShortName': 'microsoft'}, 'dataVersion': '5.1'}
CVE-2006-5014
8.80
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
none
no
total
2.0.3
2025-04-03 18:19:40.900742+03:00
['CWE-276']
2025-04-03 18:20:34.813000+03:00
012256b959432049cb378a10b753d6f992d18101eca1140b4affc09bca2e7361
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://forums.cpanel.net/showthread.php?t=58134', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://securitytracker.com/id?1016913', 'name': '1016913', 'tags': ['vdb-entry', 'x_refsource_SECTRACK', 'x_transferred']}, {'url': 'http://secunia.com/advisories/22072', 'name': '22072', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA', 'x_transferred']}, {'url': 'http://changelog.cpanel.net/?build=&showall=1', 'tags': ['x_refsource_CONFIRM', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/20163', 'name': '20163', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:32:22.871Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5014', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'no'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:19:40.900742Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-276', 'description': 'CWE-276 Incorrect Default Permissions'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:20:34.813Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://forums.cpanel.net/showthread.php?t=58134', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://securitytracker.com/id?1016913', 'name': '1016913', 'tags': ['vdb-entry', 'x_refsource_SECTRACK']}, {'url': 'http://secunia.com/advisories/22072', 'name': '22072', 'tags': ['third-party-advisory', 'x_refsource_SECUNIA']}, {'url': 'http://changelog.cpanel.net/?build=&showall=1', 'tags': ['x_refsource_CONFIRM']}, {'url': 'http://www.securityfocus.com/bid/20163', 'name': '20163', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-09-27T01:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://forums.cpanel.net/showthread.php?t=58134', 'name': 'http://forums.cpanel.net/showthread.php?t=58134', 'refsource': 'CONFIRM'}, {'url': 'http://securitytracker.com/id?1016913', 'name': '1016913', 'refsource': 'SECTRACK'}, {'url': 'http://secunia.com/advisories/22072', 'name': '22072', 'refsource': 'SECUNIA'}, {'url': 'http://changelog.cpanel.net/?build=&showall=1', 'name': 'http://changelog.cpanel.net/?build=&showall=1', 'refsource': 'CONFIRM'}, {'url': 'http://www.securityfocus.com/bid/20163', 'name': '20163', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5014', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5014', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:20:50.861Z', 'dateReserved': '2006-09-26T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-09-27T01:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-5021
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2025-04-03 18:17:19.693482+03:00
['CWE-94']
2025-04-03 18:17:59.385000+03:00
89f4d1e7fc84d67f6252a5e5fbc340afd2b62b0dd4b53a1d48812fa649216f82
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/bid/20115', 'name': '20115', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:32:22.960Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-5021', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-04-03T15:17:19.693482Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'cweId': 'CWE-94', 'description': "CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-04-03T15:17:59.385Z'}}], 'cna': {'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'references': [{'url': 'http://www.securityfocus.com/bid/20115', 'name': '20115', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2006-09-27T23:00:00.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/bid/20115', 'name': '20115', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': 'Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-5021', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-5021', 'state': 'PUBLISHED', 'dateUpdated': '2025-04-03T15:18:24.691Z', 'dateReserved': '2006-09-27T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-09-27T23:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}
CVE-2006-4428
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
none
yes
total
2.0.3
2025-01-17 17:01:37.355489+03:00
2025-01-17 17:01:18.199000+03:00
66bb8c231a7c76b75d2afca69fd2ef8fd36cddcb54eab6c520ab3a3b10bc9cb9
2026-05-29 05:09:33.454344+03:00
2026-05-29 05:09:33.454344+03:00
{'dataType': 'CVE_RECORD', 'containers': {'adp': [{'title': 'CVE Program Container', 'references': [{'url': 'http://www.securityfocus.com/archive/1/444421/100/0/threaded', 'name': '20060825 Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.osvdb.org/28298', 'name': '28298', 'tags': ['vdb-entry', 'x_refsource_OSVDB', 'x_transferred']}, {'url': 'http://www.securityfocus.com/archive/1/444729/100/0/threaded', 'name': '20060829 Re: Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ', 'x_transferred']}, {'url': 'http://www.attrition.org/pipermail/vim/2006-August/000996.html', 'name': '20060828 Jupiter CMS file include - CVE dispute', 'tags': ['mailing-list', 'x_refsource_VIM', 'x_transferred']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/28589', 'name': 'jupitercm-index-file-include(28589)', 'tags': ['vdb-entry', 'x_refsource_XF', 'x_transferred']}, {'url': 'http://www.securityfocus.com/bid/19721', 'name': '19721', 'tags': ['vdb-entry', 'x_refsource_BID', 'x_transferred']}], 'providerMetadata': {'orgId': 'af854a3a-2127-422b-91ae-364da2661108', 'shortName': 'CVE', 'dateUpdated': '2024-08-07T19:06:07.753Z'}}, {'title': 'CISA ADP Vulnrichment', 'metrics': [{'cvssV3_1': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}}, {'other': {'type': 'ssvc', 'content': {'id': 'CVE-2006-4428', 'role': 'CISA Coordinator', 'options': [{'Exploitation': 'none'}, {'Automatable': 'yes'}, {'Technical Impact': 'total'}], 'version': '2.0.3', 'timestamp': '2025-01-17T14:01:37.355489Z'}}}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'CWE', 'description': 'CWE-noinfo Not enough information'}]}], 'providerMetadata': {'orgId': '134c704f-9b21-4f2e-91b3-4a467353bcc0', 'shortName': 'CISA-ADP', 'dateUpdated': '2025-01-17T14:01:18.199Z'}}], 'cna': {'tags': ['disputed'], 'affected': [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}], 'datePublic': '2006-08-25T00:00:00.000Z', 'references': [{'url': 'http://www.securityfocus.com/archive/1/444421/100/0/threaded', 'name': '20060825 Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.osvdb.org/28298', 'name': '28298', 'tags': ['vdb-entry', 'x_refsource_OSVDB']}, {'url': 'http://www.securityfocus.com/archive/1/444729/100/0/threaded', 'name': '20060829 Re: Jupiter CMS 1.1.5 index.php Remote File Include', 'tags': ['mailing-list', 'x_refsource_BUGTRAQ']}, {'url': 'http://www.attrition.org/pipermail/vim/2006-August/000996.html', 'name': '20060828 Jupiter CMS file include - CVE dispute', 'tags': ['mailing-list', 'x_refsource_VIM']}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/28589', 'name': 'jupitercm-index-file-include(28589)', 'tags': ['vdb-entry', 'x_refsource_XF']}, {'url': 'http://www.securityfocus.com/bid/19721', 'name': '19721', 'tags': ['vdb-entry', 'x_refsource_BID']}], 'descriptions': [{'lang': 'en', 'value': 'PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement'}], 'problemTypes': [{'descriptions': [{'lang': 'en', 'type': 'text', 'description': 'n/a'}]}], 'providerMetadata': {'orgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'shortName': 'mitre', 'dateUpdated': '2018-10-17T20:57:01.000Z'}, 'x_legacyV4Record': {'affects': {'vendor': {'vendor_data': [{'product': {'product_data': [{'version': {'version_data': [{'version_value': 'n/a'}]}, 'product_name': 'n/a'}]}, 'vendor_name': 'n/a'}]}}, 'data_type': 'CVE', 'references': {'reference_data': [{'url': 'http://www.securityfocus.com/archive/1/444421/100/0/threaded', 'name': '20060825 Jupiter CMS 1.1.5 index.php Remote File Include', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.osvdb.org/28298', 'name': '28298', 'refsource': 'OSVDB'}, {'url': 'http://www.securityfocus.com/archive/1/444729/100/0/threaded', 'name': '20060829 Re: Jupiter CMS 1.1.5 index.php Remote File Include', 'refsource': 'BUGTRAQ'}, {'url': 'http://www.attrition.org/pipermail/vim/2006-August/000996.html', 'name': '20060828 Jupiter CMS file include - CVE dispute', 'refsource': 'VIM'}, {'url': 'https://exchange.xforce.ibmcloud.com/vulnerabilities/28589', 'name': 'jupitercm-index-file-include(28589)', 'refsource': 'XF'}, {'url': 'http://www.securityfocus.com/bid/19721', 'name': '19721', 'refsource': 'BID'}]}, 'data_format': 'MITRE', 'description': {'description_data': [{'lang': 'eng', 'value': '** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement.'}]}, 'problemtype': {'problemtype_data': [{'description': [{'lang': 'eng', 'value': 'n/a'}]}]}, 'data_version': '4.0', 'CVE_data_meta': {'ID': 'CVE-2006-4428', 'STATE': 'PUBLIC', 'ASSIGNER': 'cve@mitre.org'}}}}, 'cveMetadata': {'cveId': 'CVE-2006-4428', 'state': 'PUBLISHED', 'dateUpdated': '2025-01-17T14:01:42.279Z', 'dateReserved': '2006-08-28T00:00:00.000Z', 'assignerOrgId': '8254265b-2729-46b6-b9e3-3dfca2d5bfca', 'datePublished': '2006-08-29T00:00:00.000Z', 'assignerShortName': 'mitre'}, 'dataVersion': '5.1'}