Логотип exploitDog
bind:"BDU:2022-02629" OR bind:"CVE-2012-2143"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2022-02629" OR bind:"CVE-2012-2143"

Количество 10

Количество 10

fstec логотип

BDU:2022-02629

почти 13 лет назад

Уязвимость функции crypt_des операционной системы FreeBSD, позволяющая нарушителю повысить свои привилегии

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2012-2143

почти 13 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-2143

около 13 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2143

почти 13 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-2143

почти 13 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-REL ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-6rxj-38xv-j69g

около 3 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1036

почти 13 лет назад

ELSA-2012-1036: postgresql security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1037

почти 13 лет назад

ELSA-2012-1037: postgresql and postgresql84 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1047

почти 13 лет назад

ELSA-2012-1047: php53 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1046

почти 13 лет назад

ELSA-2012-1046: php security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-02629

Уязвимость функции crypt_des операционной системы FreeBSD, позволяющая нарушителю повысить свои привилегии

CVSS3: 3.7
7%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
7%
Низкий
почти 13 лет назад
redhat логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4
7%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
7%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-REL ...

CVSS2: 4.3
7%
Низкий
почти 13 лет назад
github логотип
GHSA-6rxj-38xv-j69g

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

7%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2012-1036

ELSA-2012-1036: postgresql security update (MODERATE)

почти 13 лет назад
oracle-oval логотип
ELSA-2012-1037

ELSA-2012-1037: postgresql and postgresql84 security update (MODERATE)

почти 13 лет назад
oracle-oval логотип
ELSA-2012-1047

ELSA-2012-1047: php53 security update (MODERATE)

почти 13 лет назад
oracle-oval логотип
ELSA-2012-1046

ELSA-2012-1046: php security update (MODERATE)

почти 13 лет назад

Уязвимостей на страницу