[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2018-1139":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":1047,"aliases":1048,"duplicate_of":9,"upstream":1049,"downstream":1050,"duplicates":1069,"related":1070,"reserved_at":9,"published_at":1073,"modified_at":1074,"state":1075,"summary":1076,"references_raw":1085,"kevs":1132,"epss":1133,"epss_history":1136,"metrics":1393,"affected":1412},"CVE-2018-1139","A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.",null,[11,588],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-522","Insufficiently Protected Credentials","The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.","weakness","Incomplete","Class",[19,23,77,81,156,232,313,367,397,438,497,532,584],{"id":20,"name":21,"techniques":22},"CAPEC-102","Session Sidejacking",[],{"id":24,"name":25,"techniques":26},"CAPEC-474","Signature Spoofing by Key Theft",[27],{"id":28,"name":29,"tactics":30,"countermeasures":34},"T1552.004","Private Keys",[31],{"id":32,"name":33},"TA0031","Credential Access",[35,40,45,49,54,59,63,67,72],{"id":36,"name":37,"tactic":38},"D3-CCSA","Credential Compromise Scope Analysis",{"name":39},"Detect",{"id":41,"name":42,"tactic":43},"D3-CR","Credential Revocation",{"name":44},"Evict",{"id":46,"name":47,"tactic":48},"D3-ANCI","Authentication Cache Invalidation",{"name":44},{"id":50,"name":51,"tactic":52},"D3-DUC","Decoy User Credential",{"name":53},"Deceive",{"id":55,"name":56,"tactic":57},"D3-CH","Credential Hardening",{"name":58},"Harden",{"id":60,"name":61,"tactic":62},"D3-MFA","Multi-factor Authentication",{"name":58},{"id":64,"name":65,"tactic":66},"D3-CRO","Credential Rotation",{"name":58},{"id":68,"name":69,"tactic":70},"D3-RIC","Reissue Credential",{"name":71},"Restore",{"id":73,"name":74,"tactic":75},"D3-CTS","Credential Transmission Scoping",{"name":76},"Isolate",{"id":78,"name":79,"techniques":80},"CAPEC-50","Password Recovery Exploitation",[],{"id":82,"name":83,"techniques":84},"CAPEC-509","Kerberoasting",[85],{"id":86,"name":83,"tactics":87,"countermeasures":89},"T1558.003",[88],{"id":32,"name":33},[90,94,98,102,106,110,114,118,122,124,128,130,132,134,136,138,140,144,148,150,154],{"id":91,"name":92,"tactic":93},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":39},{"id":95,"name":96,"tactic":97},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":39},{"id":99,"name":100,"tactic":101},"D3-CSPP","Client-server Payload Profiling",{"name":39},{"id":103,"name":104,"tactic":105},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":39},{"id":107,"name":108,"tactic":109},"D3-NTSA","Network Traffic Signature Analysis",{"name":39},{"id":111,"name":112,"tactic":113},"D3-APCA","Application Protocol Command Analysis",{"name":39},{"id":115,"name":116,"tactic":117},"D3-NTCD","Network Traffic Community Deviation",{"name":39},{"id":119,"name":120,"tactic":121},"D3-RTSD","Remote Terminal Session Detection",{"name":39},{"id":36,"name":37,"tactic":123},{"name":39},{"id":125,"name":126,"tactic":127},"D3-RTA","RPC Traffic Analysis",{"name":39},{"id":41,"name":42,"tactic":129},{"name":44},{"id":46,"name":47,"tactic":131},{"name":44},{"id":50,"name":51,"tactic":133},{"name":53},{"id":55,"name":56,"tactic":135},{"name":58},{"id":60,"name":61,"tactic":137},{"name":58},{"id":64,"name":65,"tactic":139},{"name":58},{"id":141,"name":142,"tactic":143},"D3-TB","Token Binding",{"name":58},{"id":145,"name":146,"tactic":147},"D3-TBA","Token-based Authentication",{"name":58},{"id":68,"name":69,"tactic":149},{"name":71},{"id":151,"name":152,"tactic":153},"D3-NTF","Network Traffic Filtering",{"name":76},{"id":73,"name":74,"tactic":155},{"name":76},{"id":157,"name":158,"techniques":159},"CAPEC-551","Modify Existing Service",[160],{"id":161,"name":162,"tactics":163,"countermeasures":170},"T1543","Create or Modify System Process",[164,167],{"id":165,"name":166},"TA0110","Persistence",{"id":168,"name":169},"TA0111","Privilege Escalation",[171,176,180,184,188,192,196,200,204,208,212,216,220,224,228],{"id":172,"name":173,"tactic":174},"D3-DI","Data Inventory",{"name":175},"Model",{"id":177,"name":178,"tactic":179},"D3-FA","File Analysis",{"name":39},{"id":181,"name":182,"tactic":183},"D3-FIM","File Integrity Monitoring",{"name":39},{"id":185,"name":186,"tactic":187},"D3-SFA","System File Analysis",{"name":39},{"id":189,"name":190,"tactic":191},"D3-FEV","File Eviction",{"name":44},{"id":193,"name":194,"tactic":195},"D3-DF","Decoy File",{"name":53},{"id":197,"name":198,"tactic":199},"D3-FE","File Encryption",{"name":58},{"id":201,"name":202,"tactic":203},"D3-SCP","System Configuration Permissions",{"name":58},{"id":205,"name":206,"tactic":207},"D3-RF","Restore File",{"name":71},{"id":209,"name":210,"tactic":211},"D3-RD","Restore Database",{"name":71},{"id":213,"name":214,"tactic":215},"D3-CF","Content Filtering",{"name":76},{"id":217,"name":218,"tactic":219},"D3-LFP","Local File Permissions",{"name":76},{"id":221,"name":222,"tactic":223},"D3-RFAM","Remote File Access Mediation",{"name":76},{"id":225,"name":226,"tactic":227},"D3-CQ","Content Quarantine",{"name":76},{"id":229,"name":230,"tactic":231},"D3-CM","Content Modification",{"name":76},{"id":233,"name":234,"techniques":235},"CAPEC-555","Remote Services with Stolen Credentials",[236,270,302],{"id":237,"name":238,"tactics":239,"countermeasures":243},"T1021","Remote Services",[240],{"id":241,"name":242},"TA0109","Lateral Movement",[244,246,248,250,252,254,256,258,260,264,268],{"id":91,"name":92,"tactic":245},{"name":39},{"id":95,"name":96,"tactic":247},{"name":39},{"id":99,"name":100,"tactic":249},{"name":39},{"id":103,"name":104,"tactic":251},{"name":39},{"id":107,"name":108,"tactic":253},{"name":39},{"id":111,"name":112,"tactic":255},{"name":39},{"id":115,"name":116,"tactic":257},{"name":39},{"id":119,"name":120,"tactic":259},{"name":39},{"id":261,"name":262,"tactic":263},"D3-CAA","Connection Attempt Analysis",{"name":39},{"id":265,"name":266,"tactic":267},"D3-ST","Session Termination",{"name":44},{"id":151,"name":152,"tactic":269},{"name":76},{"id":271,"name":272,"tactics":273,"countermeasures":277},"T1114.002","Remote Email Collection",[274],{"id":275,"name":276},"TA0100","Collection",[278,282,286,290,294,298],{"id":279,"name":280,"tactic":281},"D3-NNI","Network Node Inventory",{"name":175},{"id":283,"name":284,"tactic":285},"D3-PLM","Physical Link Mapping",{"name":175},{"id":287,"name":288,"tactic":289},"D3-LLM","Logical Link Mapping",{"name":175},{"id":291,"name":292,"tactic":293},"D3-EHB","Endpoint Health Beacon",{"name":39},{"id":295,"name":296,"tactic":297},"D3-ER","Email Removal",{"name":44},{"id":299,"name":300,"tactic":301},"D3-RNA","Restore Network Access",{"name":71},{"id":303,"name":304,"tactics":305,"countermeasures":310},"T1133","External Remote Services",[306,307],{"id":165,"name":166},{"id":308,"name":309},"TA0108","Initial Access",[311],{"id":265,"name":266,"tactic":312},{"name":44},{"id":314,"name":315,"techniques":316},"CAPEC-560","Use of Known Domain Credentials",[317],{"id":318,"name":319,"tactics":320,"countermeasures":330},"T1078","Valid Accounts",[321,324,327,328,329],{"id":322,"name":323},"TA0030","Defense Evasion",{"id":325,"name":326},"TA0005","Stealth",{"id":165,"name":166},{"id":168,"name":169},{"id":308,"name":309},[331,335,339,343,347,351,355,359,363],{"id":332,"name":333,"tactic":334},"D3-AM","Access Modeling",{"name":175},{"id":336,"name":337,"tactic":338},"D3-LAM","Local Account Monitoring",{"name":39},{"id":340,"name":341,"tactic":342},"D3-DAM","Domain Account Monitoring",{"name":39},{"id":344,"name":345,"tactic":346},"D3-AL","Account Locking",{"name":44},{"id":348,"name":349,"tactic":350},"D3-AA","Agent Authentication",{"name":58},{"id":352,"name":353,"tactic":354},"D3-CDP","Change Default Password",{"name":58},{"id":356,"name":357,"tactic":358},"D3-ULA","Unlock Account",{"name":71},{"id":360,"name":361,"tactic":362},"D3-RUAA","Restore User Account Access",{"name":71},{"id":364,"name":365,"tactic":366},"D3-UAP","User Account Permissions",{"name":76},{"id":368,"name":369,"techniques":370},"CAPEC-561","Windows Admin Shares with Stolen Credentials",[371],{"id":372,"name":373,"tactics":374,"countermeasures":376},"T1021.002","SMB/Windows Admin Shares",[375],{"id":241,"name":242},[377,379,381,383,385,387,389,391,393,395],{"id":91,"name":92,"tactic":378},{"name":39},{"id":95,"name":96,"tactic":380},{"name":39},{"id":99,"name":100,"tactic":382},{"name":39},{"id":103,"name":104,"tactic":384},{"name":39},{"id":107,"name":108,"tactic":386},{"name":39},{"id":111,"name":112,"tactic":388},{"name":39},{"id":115,"name":116,"tactic":390},{"name":39},{"id":119,"name":120,"tactic":392},{"name":39},{"id":261,"name":262,"tactic":394},{"name":39},{"id":151,"name":152,"tactic":396},{"name":76},{"id":398,"name":399,"techniques":400},"CAPEC-600","Credential Stuffing",[401],{"id":402,"name":399,"tactics":403,"countermeasures":405},"T1110.004",[404],{"id":32,"name":33},[406,410,414,416,418,420,422,424,426,428,430,432,436],{"id":407,"name":408,"tactic":409},"D3-AEM","Application Exception Monitoring",{"name":39},{"id":411,"name":412,"tactic":413},"D3-OPM","Operational Process Monitoring",{"name":39},{"id":91,"name":92,"tactic":415},{"name":39},{"id":95,"name":96,"tactic":417},{"name":39},{"id":99,"name":100,"tactic":419},{"name":39},{"id":103,"name":104,"tactic":421},{"name":39},{"id":107,"name":108,"tactic":423},{"name":39},{"id":111,"name":112,"tactic":425},{"name":39},{"id":115,"name":116,"tactic":427},{"name":39},{"id":119,"name":120,"tactic":429},{"name":39},{"id":261,"name":262,"tactic":431},{"name":39},{"id":433,"name":434,"tactic":435},"D3-ANAA","Administrative Network Activity Analysis",{"name":39},{"id":151,"name":152,"tactic":437},{"name":76},{"id":439,"name":440,"techniques":441},"CAPEC-644","Use of Captured Hashes (Pass The Hash)",[442],{"id":443,"name":444,"tactics":445,"countermeasures":448},"T1550.002","Pass the Hash",[446,447],{"id":322,"name":323},{"id":241,"name":242},[449,453,457,461,465,469,473,477,481,485,489,493],{"id":450,"name":451,"tactic":452},"D3-PLA","Process Lineage Analysis",{"name":39},{"id":454,"name":455,"tactic":456},"D3-PSMD","Process Self-Modification Detection",{"name":39},{"id":458,"name":459,"tactic":460},"D3-PSA","Process Spawn Analysis",{"name":39},{"id":462,"name":463,"tactic":464},"D3-PT","Process Termination",{"name":44},{"id":466,"name":467,"tactic":468},"D3-PS","Process Suspension",{"name":44},{"id":470,"name":471,"tactic":472},"D3-HR","Host Reboot",{"name":44},{"id":474,"name":475,"tactic":476},"D3-HS","Host Shutdown",{"name":44},{"id":478,"name":479,"tactic":480},"D3-KBPI","Kernel-based Process Isolation",{"name":76},{"id":482,"name":483,"tactic":484},"D3-SCF","System Call Filtering",{"name":76},{"id":486,"name":487,"tactic":488},"D3-HBPI","Hardware-based Process Isolation",{"name":76},{"id":490,"name":491,"tactic":492},"D3-ABPI","Application-based Process Isolation",{"name":76},{"id":494,"name":495,"tactic":496},"D3-WSAM","Web Session Access Mediation",{"name":76},{"id":498,"name":499,"techniques":500},"CAPEC-645","Use of Captured Tickets (Pass The Ticket)",[501],{"id":502,"name":503,"tactics":504,"countermeasures":507},"T1550.003","Pass the Ticket",[505,506],{"id":322,"name":323},{"id":241,"name":242},[508,510,512,514,516,518,520,522,524,526,528,530],{"id":450,"name":451,"tactic":509},{"name":39},{"id":454,"name":455,"tactic":511},{"name":39},{"id":458,"name":459,"tactic":513},{"name":39},{"id":462,"name":463,"tactic":515},{"name":44},{"id":466,"name":467,"tactic":517},{"name":44},{"id":470,"name":471,"tactic":519},{"name":44},{"id":474,"name":475,"tactic":521},{"name":44},{"id":478,"name":479,"tactic":523},{"name":76},{"id":482,"name":483,"tactic":525},{"name":76},{"id":486,"name":487,"tactic":527},{"name":76},{"id":490,"name":491,"tactic":529},{"name":76},{"id":494,"name":495,"tactic":531},{"name":76},{"id":533,"name":534,"techniques":535},"CAPEC-652","Use of Known Kerberos Credentials",[536],{"id":537,"name":538,"tactics":539,"countermeasures":541},"T1558","Steal or Forge Kerberos Tickets",[540],{"id":32,"name":33},[542,544,546,548,550,552,554,556,558,560,562,564,566,568,570,572,574,576,578,580,582],{"id":91,"name":92,"tactic":543},{"name":39},{"id":95,"name":96,"tactic":545},{"name":39},{"id":99,"name":100,"tactic":547},{"name":39},{"id":103,"name":104,"tactic":549},{"name":39},{"id":107,"name":108,"tactic":551},{"name":39},{"id":111,"name":112,"tactic":553},{"name":39},{"id":115,"name":116,"tactic":555},{"name":39},{"id":119,"name":120,"tactic":557},{"name":39},{"id":36,"name":37,"tactic":559},{"name":39},{"id":125,"name":126,"tactic":561},{"name":39},{"id":41,"name":42,"tactic":563},{"name":44},{"id":46,"name":47,"tactic":565},{"name":44},{"id":50,"name":51,"tactic":567},{"name":53},{"id":55,"name":56,"tactic":569},{"name":58},{"id":60,"name":61,"tactic":571},{"name":58},{"id":64,"name":65,"tactic":573},{"name":58},{"id":141,"name":142,"tactic":575},{"name":58},{"id":145,"name":146,"tactic":577},{"name":58},{"id":68,"name":69,"tactic":579},{"name":71},{"id":151,"name":152,"tactic":581},{"name":76},{"id":73,"name":74,"tactic":583},{"name":76},{"id":585,"name":586,"techniques":587},"CAPEC-653","Use of Known Operating System Credentials",[],{"_key":589,"id":589,"name":590,"description":591,"type":15,"status":592,"abstraction":17,"likelihood_of_exploit":593,"capec":594},"CWE-20","Improper Input Validation","The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly.","Stable","High",[595,599,603,607,611,615,619,623,768,772,776,780,784,788,792,796,800,804,808,812,816,820,861,865,869,897,901,905,909,913,917,967,971,975,979,983,987,991,995,999,1003,1007,1011,1015,1019,1023,1027,1031,1035,1039,1043],{"id":596,"name":597,"techniques":598},"CAPEC-10","Buffer Overflow via Environment Variables",[],{"id":600,"name":601,"techniques":602},"CAPEC-101","Server Side Include (SSI) Injection",[],{"id":604,"name":605,"techniques":606},"CAPEC-104","Cross Zone Scripting",[],{"id":608,"name":609,"techniques":610},"CAPEC-108","Command Line Execution through SQL Injection",[],{"id":612,"name":613,"techniques":614},"CAPEC-109","Object Relational Mapping Injection",[],{"id":616,"name":617,"techniques":618},"CAPEC-110","SQL Injection through SOAP Parameter Tampering",[],{"id":620,"name":621,"techniques":622},"CAPEC-120","Double Encoding",[],{"id":624,"name":625,"techniques":626},"CAPEC-13","Subverting Environment Variable Values",[627,692,728],{"id":628,"name":629,"tactics":630,"countermeasures":633},"T1562.003","Impair Command History Logging",[631,632],{"id":322,"name":323},{"id":325,"name":326},[634,638,640,642,646,650,652,656,658,662,666,668,672,674,676,678,680,682,684,688],{"id":635,"name":636,"tactic":637},"D3-CI","Configuration Inventory",{"name":175},{"id":177,"name":178,"tactic":639},{"name":39},{"id":181,"name":182,"tactic":641},{"name":39},{"id":643,"name":644,"tactic":645},"D3-DA","Dynamic Analysis",{"name":39},{"id":647,"name":648,"tactic":649},"D3-EFA","Emulated File Analysis",{"name":39},{"id":189,"name":190,"tactic":651},{"name":44},{"id":653,"name":654,"tactic":655},"D3-RKD","Registry Key Deletion",{"name":44},{"id":193,"name":194,"tactic":657},{"name":53},{"id":659,"name":660,"tactic":661},"D3-DRA","Disable Remote Access",{"name":58},{"id":663,"name":664,"tactic":665},"D3-ACH","Application Configuration Hardening",{"name":58},{"id":197,"name":198,"tactic":667},{"name":58},{"id":669,"name":670,"tactic":671},"D3-RC","Restore Configuration",{"name":71},{"id":205,"name":206,"tactic":673},{"name":71},{"id":225,"name":226,"tactic":675},{"name":76},{"id":213,"name":214,"tactic":677},{"name":76},{"id":217,"name":218,"tactic":679},{"name":76},{"id":221,"name":222,"tactic":681},{"name":76},{"id":229,"name":230,"tactic":683},{"name":76},{"id":685,"name":686,"tactic":687},"D3-EAL","Executable Allowlisting",{"name":76},{"id":689,"name":690,"tactic":691},"D3-EDL","Executable Denylisting",{"name":76},{"id":693,"name":694,"tactics":695,"countermeasures":703},"T1574.006","Dynamic Linker Hijacking",[696,697,698,699,700],{"id":165,"name":166},{"id":168,"name":169},{"id":322,"name":323},{"id":325,"name":326},{"id":701,"name":702},"TA0104","Execution",[704,706,708,710,712,714,716,718,720,722,724,726],{"id":185,"name":186,"tactic":705},{"name":39},{"id":177,"name":178,"tactic":707},{"name":39},{"id":181,"name":182,"tactic":709},{"name":39},{"id":189,"name":190,"tactic":711},{"name":44},{"id":193,"name":194,"tactic":713},{"name":53},{"id":197,"name":198,"tactic":715},{"name":58},{"id":205,"name":206,"tactic":717},{"name":71},{"id":213,"name":214,"tactic":719},{"name":76},{"id":217,"name":218,"tactic":721},{"name":76},{"id":221,"name":222,"tactic":723},{"name":76},{"id":225,"name":226,"tactic":725},{"name":76},{"id":229,"name":230,"tactic":727},{"name":76},{"id":729,"name":730,"tactics":731,"countermeasures":737},"T1574.007","Path Interception by PATH Environment Variable",[732,733,734,735,736],{"id":165,"name":166},{"id":168,"name":169},{"id":322,"name":323},{"id":325,"name":326},{"id":701,"name":702},[738,740,742,744,746,748,750,752,754,756,758,760,762,764,766],{"id":177,"name":178,"tactic":739},{"name":39},{"id":181,"name":182,"tactic":741},{"name":39},{"id":643,"name":644,"tactic":743},{"name":39},{"id":647,"name":648,"tactic":745},{"name":39},{"id":189,"name":190,"tactic":747},{"name":44},{"id":193,"name":194,"tactic":749},{"name":53},{"id":197,"name":198,"tactic":751},{"name":58},{"id":205,"name":206,"tactic":753},{"name":71},{"id":213,"name":214,"tactic":755},{"name":76},{"id":217,"name":218,"tactic":757},{"name":76},{"id":221,"name":222,"tactic":759},{"name":76},{"id":225,"name":226,"tactic":761},{"name":76},{"id":229,"name":230,"tactic":763},{"name":76},{"id":685,"name":686,"tactic":765},{"name":76},{"id":689,"name":690,"tactic":767},{"name":76},{"id":769,"name":770,"techniques":771},"CAPEC-135","Format String Injection",[],{"id":773,"name":774,"techniques":775},"CAPEC-136","LDAP Injection",[],{"id":777,"name":778,"techniques":779},"CAPEC-14","Client-side Injection-induced Buffer Overflow",[],{"id":781,"name":782,"techniques":783},"CAPEC-153","Input Data Manipulation",[],{"id":785,"name":786,"techniques":787},"CAPEC-182","Flash Injection",[],{"id":789,"name":790,"techniques":791},"CAPEC-209","XSS Using MIME Type Mismatch",[],{"id":793,"name":794,"techniques":795},"CAPEC-22","Exploiting Trust in Client",[],{"id":797,"name":798,"techniques":799},"CAPEC-23","File Content Injection",[],{"id":801,"name":802,"techniques":803},"CAPEC-230","Serialized Data with Nested Payloads",[],{"id":805,"name":806,"techniques":807},"CAPEC-231","Oversized Serialized Data Payloads",[],{"id":809,"name":810,"techniques":811},"CAPEC-24","Filter Failure through Buffer Overflow",[],{"id":813,"name":814,"techniques":815},"CAPEC-250","XML Injection",[],{"id":817,"name":818,"techniques":819},"CAPEC-261","Fuzzing for garnering other adjacent user/sensitive data",[],{"id":821,"name":822,"techniques":823},"CAPEC-267","Leverage Alternate Encoding",[824],{"id":825,"name":826,"tactics":827,"countermeasures":830},"T1027","Obfuscated Files or Information",[828,829],{"id":322,"name":323},{"id":325,"name":326},[831,833,835,837,839,841,843,845,847,849,851,853,855,857,859],{"id":177,"name":178,"tactic":832},{"name":39},{"id":181,"name":182,"tactic":834},{"name":39},{"id":643,"name":644,"tactic":836},{"name":39},{"id":647,"name":648,"tactic":838},{"name":39},{"id":189,"name":190,"tactic":840},{"name":44},{"id":193,"name":194,"tactic":842},{"name":53},{"id":197,"name":198,"tactic":844},{"name":58},{"id":205,"name":206,"tactic":846},{"name":71},{"id":213,"name":214,"tactic":848},{"name":76},{"id":217,"name":218,"tactic":850},{"name":76},{"id":221,"name":222,"tactic":852},{"name":76},{"id":225,"name":226,"tactic":854},{"name":76},{"id":229,"name":230,"tactic":856},{"name":76},{"id":685,"name":686,"tactic":858},{"name":76},{"id":689,"name":690,"tactic":860},{"name":76},{"id":862,"name":863,"techniques":864},"CAPEC-28","Fuzzing",[],{"id":866,"name":867,"techniques":868},"CAPEC-3","Using Leading 'Ghost' Character Sequences to Bypass Input Filters",[],{"id":870,"name":871,"techniques":872},"CAPEC-31","Accessing/Intercepting/Modifying HTTP Cookies",[873],{"id":874,"name":875,"tactics":876,"countermeasures":878},"T1539","Steal Web Session Cookie",[877],{"id":32,"name":33},[879,881,883,885,887,889,891,893,895],{"id":36,"name":37,"tactic":880},{"name":39},{"id":41,"name":42,"tactic":882},{"name":44},{"id":46,"name":47,"tactic":884},{"name":44},{"id":50,"name":51,"tactic":886},{"name":53},{"id":55,"name":56,"tactic":888},{"name":58},{"id":60,"name":61,"tactic":890},{"name":58},{"id":64,"name":65,"tactic":892},{"name":58},{"id":68,"name":69,"tactic":894},{"name":71},{"id":73,"name":74,"tactic":896},{"name":76},{"id":898,"name":899,"techniques":900},"CAPEC-42","MIME Conversion",[],{"id":902,"name":903,"techniques":904},"CAPEC-43","Exploiting Multiple Input Interpretation Layers",[],{"id":906,"name":907,"techniques":908},"CAPEC-45","Buffer Overflow via Symbolic Links",[],{"id":910,"name":911,"techniques":912},"CAPEC-46","Overflow Variables and Tags",[],{"id":914,"name":915,"techniques":916},"CAPEC-47","Buffer Overflow via Parameter Expansion",[],{"id":918,"name":919,"techniques":920},"CAPEC-473","Signature Spoof",[921,958],{"id":922,"name":923,"tactics":924,"countermeasures":927},"T1036.001","Invalid Code Signature",[925,926],{"id":322,"name":323},{"id":325,"name":326},[928,930,932,934,936,938,940,942,944,946,948,950,952,954,956],{"id":177,"name":178,"tactic":929},{"name":39},{"id":181,"name":182,"tactic":931},{"name":39},{"id":643,"name":644,"tactic":933},{"name":39},{"id":647,"name":648,"tactic":935},{"name":39},{"id":189,"name":190,"tactic":937},{"name":44},{"id":193,"name":194,"tactic":939},{"name":53},{"id":197,"name":198,"tactic":941},{"name":58},{"id":205,"name":206,"tactic":943},{"name":71},{"id":213,"name":214,"tactic":945},{"name":76},{"id":217,"name":218,"tactic":947},{"name":76},{"id":221,"name":222,"tactic":949},{"name":76},{"id":225,"name":226,"tactic":951},{"name":76},{"id":229,"name":230,"tactic":953},{"name":76},{"id":685,"name":686,"tactic":955},{"name":76},{"id":689,"name":690,"tactic":957},{"name":76},{"id":959,"name":960,"tactics":961,"countermeasures":966},"T1553.002","Code Signing",[962,963],{"id":322,"name":323},{"id":964,"name":965},"TA0112","Defense Impairment",[],{"id":968,"name":969,"techniques":970},"CAPEC-52","Embedding NULL Bytes",[],{"id":972,"name":973,"techniques":974},"CAPEC-53","Postfix, Null Terminate, and Backslash",[],{"id":976,"name":977,"techniques":978},"CAPEC-588","DOM-Based XSS",[],{"id":980,"name":981,"techniques":982},"CAPEC-63","Cross-Site Scripting (XSS)",[],{"id":984,"name":985,"techniques":986},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":988,"name":989,"techniques":990},"CAPEC-664","Server Side Request Forgery",[],{"id":992,"name":993,"techniques":994},"CAPEC-67","String Format Overflow in syslog()",[],{"id":996,"name":997,"techniques":998},"CAPEC-7","Blind SQL Injection",[],{"id":1000,"name":1001,"techniques":1002},"CAPEC-71","Using Unicode Encoding to Bypass Validation Logic",[],{"id":1004,"name":1005,"techniques":1006},"CAPEC-72","URL Encoding",[],{"id":1008,"name":1009,"techniques":1010},"CAPEC-73","User-Controlled Filename",[],{"id":1012,"name":1013,"techniques":1014},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":1016,"name":1017,"techniques":1018},"CAPEC-79","Using Slashes in Alternate Encoding",[],{"id":1020,"name":1021,"techniques":1022},"CAPEC-8","Buffer Overflow in an API Call",[],{"id":1024,"name":1025,"techniques":1026},"CAPEC-80","Using UTF-8 Encoding to Bypass Validation Logic",[],{"id":1028,"name":1029,"techniques":1030},"CAPEC-81","Web Server Logs Tampering",[],{"id":1032,"name":1033,"techniques":1034},"CAPEC-83","XPath Injection",[],{"id":1036,"name":1037,"techniques":1038},"CAPEC-85","AJAX Footprinting",[],{"id":1040,"name":1041,"techniques":1042},"CAPEC-88","OS Command Injection",[],{"id":1044,"name":1045,"techniques":1046},"CAPEC-9","Buffer Overflow in Local Command-Line Utilities",[],[],[],[],[1051,1053,1055,1057,1059,1061,1063,1065,1067],{"_key":1052},"ALPINE-CVE-2018-1139",{"_key":1054},"SUSE-SU-2018:2318-1",{"_key":1056},"OPENSUSE-SU-2024:11365-1",{"_key":1058},"RHSA-2018:2612",{"_key":1060},"RHSA-2018:2613",{"_key":1062},"RHSA-2018:3056",{"_key":1064},"UBUNTU-CVE-2018-1139",{"_key":1066},"USN-3738-1",{"_key":1068},"DEBIAN-CVE-2018-1139",[],[1071,1072],{"_key":1054},{"_key":1056},"2018-08-22T14:00:00.000Z","2024-08-05T03:51:48.837Z","Modified",{"cisa_kev":1077,"cisa_ransomware":1077,"cisa_vendor":9,"epss_severity":1078,"epss_score":1079,"severity":1080,"severity_score":1081,"severity_version":1082,"severity_source":1083,"severity_vector":1084,"severity_status":1075},false,"low",0.0162,"high",8.1,"v3.1","nvd","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",[1086,1094,1099,1103,1109,1115,1119,1123,1127],{"url":1087,"sources":1088,"tags":1090},"https://access.redhat.com/errata/RHSA-2018:2613",[1089,1083],"cve.org",[1091,1092,1093],"Vendor Advisory","X Refsource REDHAT","Third Party Advisory",{"url":1095,"sources":1096,"tags":1097},"https://usn.ubuntu.com/3738-1/",[1089,1083],[1091,1098,1093],"X Refsource UBUNTU",{"url":1100,"sources":1101,"tags":1102},"https://access.redhat.com/errata/RHSA-2018:2612",[1089,1083],[1091,1092,1093],{"url":1104,"sources":1105,"tags":1106},"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1139",[1089,1083],[1107,1108,1093],"X Refsource CONFIRM","Issue Tracking",{"url":1110,"sources":1111,"tags":1112},"http://www.securityfocus.com/bid/105084",[1089,1083],[1113,1114,1093],"VDB Entry","X Refsource BID",{"url":1116,"sources":1117,"tags":1118},"https://access.redhat.com/errata/RHSA-2018:3056",[1089,1083],[1091,1092,1093],{"url":1120,"sources":1121,"tags":1122},"https://security.netapp.com/advisory/ntap-20180814-0001/",[1089,1083],[1107,1093],{"url":1124,"sources":1125,"tags":1126},"https://www.samba.org/samba/security/CVE-2018-1139.html",[1089,1083],[1107,1093],{"url":1128,"sources":1129,"tags":1130},"https://security.gentoo.org/glsa/202003-52",[1089,1083],[1091,1131,1093],"X Refsource GENTOO",[],{"date":1134,"score":1079,"percentile":1135},"2026-06-04",0.82164,[1137,1141,1144,1147,1150,1153,1155,1157,1160,1163,1166,1169,1172,1175,1177,1181,1185,1188,1191,1193,1196,1199,1202,1204,1206,1209,1212,1216,1219,1222,1225,1228,1231,1234,1236,1239,1242,1245,1248,1251,1253,1256,1259,1262,1265,1268,1271,1273,1276,1279,1282,1285,1288,1290,1294,1297,1300,1303,1306,1309,1312,1315,1318,1320,1323,1325,1328,1331,1334,1337,1339,1341,1344,1347,1350,1353,1356,1358,1361,1363,1366,1369,1372,1374,1376,1379,1382,1385,1388,1390],{"date":1138,"score":1139,"percentile":1140},"2025-11-04",0.02605,0.85096,{"date":1142,"score":1139,"percentile":1143},"2025-11-05",0.85099,{"date":1145,"score":1139,"percentile":1146},"2025-11-06",0.85102,{"date":1148,"score":1139,"percentile":1149},"2025-11-07",0.85109,{"date":1151,"score":1139,"percentile":1152},"2025-11-08",0.85114,{"date":1154,"score":1139,"percentile":1149},"2025-11-09",{"date":1156,"score":1139,"percentile":1146},"2025-11-10",{"date":1158,"score":1139,"percentile":1159},"2025-11-11",0.85107,{"date":1161,"score":1139,"percentile":1162},"2025-11-12",0.85119,{"date":1164,"score":1139,"percentile":1165},"2025-11-13",0.85125,{"date":1167,"score":1139,"percentile":1168},"2025-11-14",0.85127,{"date":1170,"score":1139,"percentile":1171},"2025-11-15",0.85121,{"date":1173,"score":1139,"percentile":1174},"2025-11-16",0.8512,{"date":1176,"score":1139,"percentile":1159},"2025-11-17",{"date":1178,"score":1179,"percentile":1180},"2025-11-18",0.01123,0.76406,{"date":1182,"score":1183,"percentile":1184},"2025-11-19",0.01079,0.75962,{"date":1186,"score":1183,"percentile":1187},"2025-11-20",0.75972,{"date":1189,"score":1139,"percentile":1190},"2025-11-21",0.85124,{"date":1192,"score":1139,"percentile":1174},"2025-11-22",{"date":1194,"score":1139,"percentile":1195},"2025-11-23",0.8511,{"date":1197,"score":1139,"percentile":1198},"2025-11-24",0.85111,{"date":1200,"score":1139,"percentile":1201},"2025-11-25",0.85112,{"date":1203,"score":1139,"percentile":1152},"2025-11-26",{"date":1205,"score":1139,"percentile":1152},"2025-11-27",{"date":1207,"score":1139,"percentile":1208},"2025-11-28",0.85097,{"date":1210,"score":1139,"percentile":1211},"2025-11-29",0.85143,{"date":1213,"score":1214,"percentile":1215},"2025-11-30",0.01526,0.80718,{"date":1217,"score":1214,"percentile":1218},"2025-12-01",0.80804,{"date":1220,"score":1214,"percentile":1221},"2025-12-02",0.80807,{"date":1223,"score":1214,"percentile":1224},"2025-12-03",0.80806,{"date":1226,"score":1214,"percentile":1227},"2025-12-04",0.80719,{"date":1229,"score":1214,"percentile":1230},"2025-12-05",0.80728,{"date":1232,"score":1214,"percentile":1233},"2025-12-06",0.80731,{"date":1235,"score":1214,"percentile":1233},"2025-12-07",{"date":1237,"score":1214,"percentile":1238},"2025-12-08",0.80734,{"date":1240,"score":1214,"percentile":1241},"2025-12-09",0.80747,{"date":1243,"score":1214,"percentile":1244},"2025-12-10",0.80774,{"date":1246,"score":1214,"percentile":1247},"2025-12-11",0.80786,{"date":1249,"score":1214,"percentile":1250},"2025-12-12",0.808,{"date":1252,"score":1214,"percentile":1250},"2025-12-13",{"date":1254,"score":1214,"percentile":1255},"2025-12-14",0.80798,{"date":1257,"score":1214,"percentile":1258},"2025-12-15",0.80795,{"date":1260,"score":1214,"percentile":1261},"2025-12-16",0.80805,{"date":1263,"score":1214,"percentile":1264},"2025-12-17",0.80814,{"date":1266,"score":1214,"percentile":1267},"2025-12-18",0.80833,{"date":1269,"score":1214,"percentile":1270},"2025-12-19",0.80839,{"date":1272,"score":1214,"percentile":1267},"2025-12-20",{"date":1274,"score":1214,"percentile":1275},"2025-12-21",0.80828,{"date":1277,"score":1214,"percentile":1278},"2025-12-22",0.80826,{"date":1280,"score":1214,"percentile":1281},"2025-12-23",0.80829,{"date":1283,"score":1214,"percentile":1284},"2025-12-24",0.80843,{"date":1286,"score":1214,"percentile":1287},"2025-12-25",0.80861,{"date":1289,"score":1214,"percentile":1287},"2025-12-26",{"date":1291,"score":1292,"percentile":1293},"2025-12-27",0.01738,0.82066,{"date":1295,"score":1214,"percentile":1296},"2025-12-28",0.80848,{"date":1298,"score":1214,"percentile":1299},"2025-12-29",0.80846,{"date":1301,"score":1214,"percentile":1302},"2025-12-30",0.80853,{"date":1304,"score":1214,"percentile":1305},"2025-12-31",0.80866,{"date":1307,"score":1214,"percentile":1308},"2026-01-01",0.80948,{"date":1310,"score":1214,"percentile":1311},"2026-01-02",0.80946,{"date":1313,"score":1214,"percentile":1314},"2026-01-03",0.80942,{"date":1316,"score":1214,"percentile":1317},"2026-01-04",0.80852,{"date":1319,"score":1214,"percentile":1299},"2026-01-05",{"date":1321,"score":1214,"percentile":1322},"2026-01-06",0.8085,{"date":1324,"score":1214,"percentile":1317},"2026-01-07",{"date":1326,"score":1214,"percentile":1327},"2026-01-08",0.80862,{"date":1329,"score":1214,"percentile":1330},"2026-01-09",0.80863,{"date":1332,"score":1214,"percentile":1333},"2026-01-10",0.80864,{"date":1335,"score":1214,"percentile":1336},"2026-01-11",0.80857,{"date":1338,"score":1214,"percentile":1296},"2026-01-12",{"date":1340,"score":1214,"percentile":1299},"2026-01-13",{"date":1342,"score":1214,"percentile":1343},"2026-01-14",0.80868,{"date":1345,"score":1214,"percentile":1346},"2026-01-15",0.80867,{"date":1348,"score":1214,"percentile":1349},"2026-01-16",0.80877,{"date":1351,"score":1214,"percentile":1352},"2026-01-17",0.80884,{"date":1354,"score":1214,"percentile":1355},"2026-01-18",0.80875,{"date":1357,"score":1214,"percentile":1343},"2026-01-19",{"date":1359,"score":1214,"percentile":1360},"2026-01-20",0.8087,{"date":1362,"score":1214,"percentile":1349},"2026-01-21",{"date":1364,"score":1214,"percentile":1365},"2026-01-22",0.80886,{"date":1367,"score":1214,"percentile":1368},"2026-01-23",0.80911,{"date":1370,"score":1214,"percentile":1371},"2026-01-24",0.80918,{"date":1373,"score":1214,"percentile":1368},"2026-01-25",{"date":1375,"score":1214,"percentile":1368},"2026-01-26",{"date":1377,"score":1214,"percentile":1378},"2026-01-27",0.80915,{"date":1380,"score":1214,"percentile":1381},"2026-01-28",0.80913,{"date":1383,"score":1214,"percentile":1384},"2026-01-29",0.80909,{"date":1386,"score":1214,"percentile":1387},"2026-01-30",0.80908,{"date":1389,"score":1214,"percentile":1378},"2026-01-31",{"date":1391,"score":1214,"percentile":1392},"2026-02-01",0.81002,[1394,1401],{"source":1089,"cvss_v2_0":9,"cvss_v3_0":1395,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":1396,"baseSeverity":1397,"vectorString":1398,"impactScore":1399,"exploitabilityScore":1400},5.4,"MEDIUM","CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",4.2,7.2,{"source":1083,"cvss_v2_0":1402,"cvss_v3_0":1407,"cvss_v3_1":1408,"cvss_v4_0":9},{"baseScore":1403,"baseSeverity":9,"vectorString":1404,"impactScore":1405,"exploitabilityScore":1406},4.3,"AV:N/AC:M/Au:N/C:P/I:N/A:N",2.9,8.6,{"baseScore":1396,"baseSeverity":1397,"vectorString":1398,"impactScore":1399,"exploitabilityScore":1400},{"baseScore":1081,"baseSeverity":1409,"vectorString":1084,"impactScore":1410,"exploitabilityScore":1411},"HIGH",9.8,5.6,[1413,1426,1433,1438,1443,1458],{"ecosystem":9,"name":1414,"vendor":1415,"product":1416,"cpe_part":1417,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1418},"ubuntu linux","canonical","ubuntu_linux","o",[1419,1422,1424],{"version":1420,"is_range":1077,"range_type":1421,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"14.04","cpe",{"version":1423,"is_range":1077,"range_type":1421,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"16.04",{"version":1425,"is_range":1077,"range_type":1421,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"18.04",{"ecosystem":9,"name":1427,"vendor":1428,"product":1429,"cpe_part":1417,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1430},"enterprise linux desktop","redhat","enterprise_linux_desktop",[1431],{"version":1432,"is_range":1077,"range_type":1421,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0",{"ecosystem":9,"name":1434,"vendor":1428,"product":1435,"cpe_part":1417,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1436},"enterprise linux server","enterprise_linux_server",[1437],{"version":1432,"is_range":1077,"range_type":1421,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"ecosystem":9,"name":1439,"vendor":1428,"product":1440,"cpe_part":1417,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1441},"enterprise linux workstation","enterprise_linux_workstation",[1442],{"version":1432,"is_range":1077,"range_type":1421,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"ecosystem":9,"name":1444,"vendor":1444,"product":1444,"cpe_part":1445,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1446},"samba","a",[1447,1454],{"version":1448,"is_range":1449,"range_type":1421,"version_start":1450,"version_start_type":1451,"version_end":1452,"version_end_type":1453,"fixed_in":9},"gte4.7.0_lt4.7.9",true,"4.7.0","including","4.7.9","excluding",{"version":1455,"is_range":1449,"range_type":1421,"version_start":1456,"version_start_type":1451,"version_end":1457,"version_end_type":1453,"fixed_in":9},"gte4.8.0_lt4.8.4","4.8.0","4.8.4",{"ecosystem":9,"name":1444,"vendor":1459,"product":1444,"cpe_part":1445,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1460},"the samba team",[1461,1463],{"version":1462,"is_range":1449,"range_type":1089,"version_start":9,"version_start_type":9,"version_end":1452,"version_end_type":1453,"fixed_in":9},"before 4.7.9",{"version":1464,"is_range":1449,"range_type":1089,"version_start":9,"version_start_type":9,"version_end":1457,"version_end_type":1453,"fixed_in":9},"before 4.8.4"]