Total vulnerabilities in the database
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Software | From | Fixed in |
---|---|---|
haxx / curl | - | 7.65.1.x |
oracle / http_server | 12.2.1.3.0 | 12.2.1.3.0.x |
oracle / enterprise_manager_ops_center | 12.3.3 | 12.3.3.x |
oracle / enterprise_manager_ops_center | 12.4.0 | 12.4.0.x |
oracle / oss_support_tools | 20.0 | 20.0.x |
oracle / http_server | 12.2.1.4.0 | 12.2.1.4.0.x |
oracle / mysql_server | 8.0.0 | 8.0.17.x |
oracle / mysql_server | 5.0.0 | 5.7.27.x |
netapp / oncommand_unified_manager | 7.3 | 7.3.x |
netapp / oncommand_unified_manager | 9.5 | 9.5.x |