Ericsson

Codechecker

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 28.10.2025 18:49:49
  • Zuletzt bearbeitet 14.11.2025 18:52:30

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed ...

  • EPSS 0.1%
  • Veröffentlicht 28.02.2025 13:15:27
  • Zuletzt bearbeitet 14.11.2025 15:29:28

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 21.01.2025 15:15:13
  • Zuletzt bearbeitet 14.11.2025 15:30:12

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a logged in user, and use the web AP...

  • EPSS 70.46%
  • Veröffentlicht 06.11.2024 15:15:11
  • Zuletzt bearbeitet 14.11.2025 16:36:09

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints o...

  • EPSS 0.29%
  • Veröffentlicht 06.11.2024 15:15:11
  • Zuletzt bearbeitet 14.11.2025 17:24:08

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up un...

Exploit
  • EPSS 0.81%
  • Veröffentlicht 24.06.2024 18:15:10
  • Zuletzt bearbeitet 21.11.2024 08:33:51

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attacker, using a path traversal at...

Exploit
  • EPSS 0.74%
  • Veröffentlicht 18.01.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:36

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService...