This page aggregates publicly disclosed CVE and security risk information related to sup, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2004-0451 | Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog. | [email protected] | 10.0 | 3.66% | 2004-12-06 | 2026-04-16 |
| CVE-2003-0606 | sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files. | [email protected] | 4.6 | 0.06% | 2003-08-27 | 2026-04-16 |