Логотип exploitDog
bind:CVE-2016-1587
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-1587

Количество 3

Количество 3

ubuntu логотип

CVE-2016-1587

почти 7 лет назад

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2016-1587

почти 7 лет назад

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-7xcr-378w-qqg3

больше 3 лет назад

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-1587

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS3: 7.1
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2016-1587

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS3: 7.1
0%
Низкий
почти 7 лет назад
github логотип
GHSA-7xcr-378w-qqg3

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу