7.2
CVE-2013-0347
- EPSS 0.48%
- Veröffentlicht 16.11.2014 11:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by reading the file.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.378 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://osvdb.org/90585
http://seclists.org/oss-sec/2013/q1/404
http://seclists.org/oss-sec/2013/q1/405
http://seclists.org/oss-sec/2013/q1/415
http://www.securityfocus.com/bid/58126
https://exchange.xforce.ibmcloud.com/vulnerabilities/82356