Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Metasploit Subscribe
Filtered by product Metasploit Framework
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2482 1 Metasploit 1 Metasploit Framework 2017-07-10 5.0 MEDIUM N/A
The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.
CVE-2011-1056 2 Metasploit, Microsoft 2 Metasploit Framework, Windows 2011-06-19 6.2 MEDIUM N/A
The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.