Status
Products
3- 6 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-4660 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2019 | Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. | ||
| CVE-2010-4659 | Med | 0.40 | 6.1 | 0.01 | Nov 20, 2019 | Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents. | ||
| CVE-2011-3370 | Med | 0.40 | 6.1 | 0.01 | Nov 12, 2019 | statusnet before 0.9.9 has XSS | ||
| CVE-2023-25780 | Med | 0.37 | 5.7 | 0.00 | Jun 2, 2023 | It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence. | ||
| CVE-2010-4658 | Med | 0.35 | 5.3 | 0.01 | Feb 7, 2020 | statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks. | ||
| CVE-2019-12164 | Cri | 0.00 | 9.8 | 0.04 | Jul 23, 2019 | ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution. | ||
| CVE-2013-4137 | 0.00 | — | 0.01 | Oct 11, 2013 | Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format." | |||
| CVE-2011-3802 | 0.00 | — | 0.01 | Sep 24, 2011 | StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files. |
- risk 0.64cvss 9.8epss 0.01
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
- risk 0.40cvss 6.1epss 0.01
statusnet before 0.9.9 has XSS
- risk 0.37cvss 5.7epss 0.00
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
- risk 0.35cvss 5.3epss 0.01
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
- risk 0.00cvss 9.8epss 0.04
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
- CVE-2013-4137Oct 11, 2013risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
- CVE-2011-3802Sep 24, 2011risk 0.00cvss —epss 0.01
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.