Логотип exploitDog
bind:CVE-2017-16667
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-16667

Количество 5

Количество 5

ubuntu логотип

CVE-2017-16667

больше 8 лет назад

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2017-16667

больше 8 лет назад

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2017-16667

больше 8 лет назад

backintime (aka Back in Time) before 1.1.24 did improper escaping/quot ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:3096-1

около 8 лет назад

Security update for backintime

EPSS: Низкий
github логотип

GHSA-pv66-pfcm-qv9x

больше 3 лет назад

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-16667

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-16667

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-16667

backintime (aka Back in Time) before 1.1.24 did improper escaping/quot ...

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:3096-1

Security update for backintime

0%
Низкий
около 8 лет назад
github логотип
GHSA-pv66-pfcm-qv9x

backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу