Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-34009

Опубликовано: 28 июл. 2022
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:fossil-scm:fossil:2.18:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00261
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

CVSS3: 5.5
debian
больше 3 лет назад

Fossil 2.18 on Windows allows attackers to cause a denial of service ( ...

CVSS3: 5.5
github
больше 3 лет назад

Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

EPSS

Процентиль: 49%
0.00261
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-79