VYPR

Kiwix

by Kiwix

CVEs (5)

  • CVE-2017-17532HigDec 14, 2017
    risk 0.57cvss 8.8epss 0.02

    examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

  • CVE-2021-35233MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the…

  • CVE-2022-27920MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.

  • CVE-2015-1032Jan 21, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search.

  • CVE-2011-4192Apr 16, 2014
    risk 0.00cvss epss 0.01

    kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."