Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-4x2g-x3r2-29r6

больше 4 лет назад

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-10070

больше 8 лет назад

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2014-10070

больше 8 лет назад

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

EPSS: Низкий
nvd логотип

CVE-2014-10070

больше 8 лет назад

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2014-10070

больше 8 лет назад

zsh before 5.0.7 allows evaluation of the initial values of integer va ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:1093-1

больше 8 лет назад

Security update for zsh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1072-1

больше 8 лет назад

Security update for zsh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:14910-1

больше 4 лет назад

Security update for zsh

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4x2g-x3r2-29r6

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2014-10070

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2014-10070

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2014-10070

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2014-10070

zsh before 5.0.7 allows evaluation of the initial values of integer va ...

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:1093-1

Security update for zsh

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2018:1072-1

Security update for zsh

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2022:14910-1

Security update for zsh

больше 4 лет назад

Уязвимостей на страницу