Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6772

Опубликовано: 27 дек. 2006
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:w3m:w3m:0.5.1:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.13757
Средний

9.3 Critical

CVSS2

Дефекты

CWE-134

Связанные уязвимости

ubuntu
почти 19 лет назад

Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.

redhat
почти 19 лет назад

Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.

debian
почти 19 лет назад

Format string vulnerability in the inputAnswer function in file.c in w ...

github
больше 3 лет назад

Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.

fstec
почти 11 лет назад

Уязвимость операционной системы openSUSE, позволяющая злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 94%
0.13757
Средний

9.3 Critical

CVSS2

Дефекты

CWE-134