Vendor
Irods
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38462 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2024 | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference. | ||
| CVE-2017-8799 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2017 | Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames. To exploit this vulnerability, a virtual iRODS pathname that includes a semicolon… | ||
| CVE-2024-38461 | Hig | 0.49 | 7.5 | 0.00 | Jun 16, 2024 | irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory. | ||
| CVE-2012-5895 | 0.00 | — | 0.02 | Nov 17, 2012 | Multiple unspecified vulnerabilities in iRODS before 3.1 have unknown impact and attack vectors. |
- risk 0.64cvss 9.8epss 0.01
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
- risk 0.64cvss 9.8epss 0.02
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames. To exploit this vulnerability, a virtual iRODS pathname that includes a semicolon…
- risk 0.49cvss 7.5epss 0.00
irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.
- CVE-2012-5895Nov 17, 2012risk 0.00cvss —epss 0.02
Multiple unspecified vulnerabilities in iRODS before 3.1 have unknown impact and attack vectors.