Логотип exploitDog
bind:"GHSA-55cc-h8m2-x3mp" OR bind:"CVE-2014-6277"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-55cc-h8m2-x3mp" OR bind:"CVE-2014-6277"

Количество 15

Количество 15

github логотип

GHSA-55cc-h8m2-x3mp

около 3 лет назад

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

EPSS: Высокий
ubuntu логотип

CVE-2014-6277

больше 10 лет назад

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

CVSS2: 10
EPSS: Высокий
redhat логотип

CVE-2014-6277

больше 10 лет назад

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2014-6277

больше 10 лет назад

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

CVSS2: 10
EPSS: Высокий
debian логотип

CVE-2014-6277

больше 10 лет назад

GNU Bash through 4.3 bash43-026 does not properly parse function defin ...

CVSS2: 10
EPSS: Высокий
oracle-oval логотип

ELSA-2014-3094

больше 10 лет назад

ELSA-2014-3094: bash security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-3093

больше 10 лет назад

ELSA-2014-3093: bash security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-3092

больше 10 лет назад

ELSA-2014-3092: bash security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:2961-1

больше 8 лет назад

Security update for bash

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2872-1

больше 8 лет назад

Security update for bash

EPSS: Низкий
fstec логотип

BDU:2015-09818

около 10 лет назад

Уязвимости операционной системы Альт Линукс СПТ, позволяющие удаленному злоумышленнику нарушить работоспособность устройства

CVSS2: 10
EPSS: Низкий
fstec логотип

BDU:2015-09794

больше 10 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 10
EPSS: Низкий
fstec логотип

BDU:2014-00319

больше 10 лет назад

Уязвимость интерпретатора командной строки GNU Bash, позволяющая злоумышленнику вызвать отказ в обслуживании или выполнить произвольный код

CVSS2: 10
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2699-1

больше 7 лет назад

Security update for SLES 12 Docker image

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2700-1

больше 7 лет назад

Security update for SLES 12-SP1 Docker image

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-55cc-h8m2-x3mp

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

86%
Высокий
около 3 лет назад
ubuntu логотип
CVE-2014-6277

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

CVSS2: 10
86%
Высокий
больше 10 лет назад
redhat логотип
CVE-2014-6277

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

CVSS2: 7.5
86%
Высокий
больше 10 лет назад
nvd логотип
CVE-2014-6277

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

CVSS2: 10
86%
Высокий
больше 10 лет назад
debian логотип
CVE-2014-6277

GNU Bash through 4.3 bash43-026 does not properly parse function defin ...

CVSS2: 10
86%
Высокий
больше 10 лет назад
oracle-oval логотип
ELSA-2014-3094

ELSA-2014-3094: bash security update (IMPORTANT)

больше 10 лет назад
oracle-oval логотип
ELSA-2014-3093

ELSA-2014-3093: bash security update (IMPORTANT)

больше 10 лет назад
oracle-oval логотип
ELSA-2014-3092

ELSA-2014-3092: bash security update (IMPORTANT)

больше 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:2961-1

Security update for bash

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:2872-1

Security update for bash

больше 8 лет назад
fstec логотип
BDU:2015-09818

Уязвимости операционной системы Альт Линукс СПТ, позволяющие удаленному злоумышленнику нарушить работоспособность устройства

CVSS2: 10
около 10 лет назад
fstec логотип
BDU:2015-09794

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 10
больше 10 лет назад
fstec логотип
BDU:2014-00319

Уязвимость интерпретатора командной строки GNU Bash, позволяющая злоумышленнику вызвать отказ в обслуживании или выполнить произвольный код

CVSS2: 10
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2017:2699-1

Security update for SLES 12 Docker image

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2017:2700-1

Security update for SLES 12-SP1 Docker image

больше 7 лет назад

Уязвимостей на страницу