VYPR

Base

by Sas

CVEs (6)

  • CVE-2019-14678CriNov 14, 2019
    risk 0.65cvss 10.0epss 0.03

    SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This…

  • CVE-2014-2262Mar 1, 2014
    risk 0.00cvss epss 0.04

    Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS program.

  • CVE-2002-2017Dec 31, 2002
    risk 0.00cvss epss 0.02

    sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.

  • CVE-2002-2018Dec 31, 2002
    risk 0.00cvss epss 0.00

    sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.

  • CVE-2002-0219May 16, 2002
    risk 0.00cvss epss 0.01

    Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.

  • CVE-2002-0218May 16, 2002
    risk 0.00cvss epss 0.00

    Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.