Fishshell / Fish
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-49284 | Command substitution output can trigger shell expansion in fish shell | MEDIUM | 6.6 | Dec 4, 2023 |
| CVE-2022-20001 | Injection in fish | HIGH | 7.8 | Mar 14, 2022 |
| CVE-2014-2906 | The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands… | HIGH | 7.0 | Jan 28, 2020 |
| CVE-2014-3856 | The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a te… | HIGH | 7.0 | Jan 28, 2020 |
| CVE-2014-2914 | fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbi… | CRITICAL | 9.8 | Jan 28, 2020 |
| CVE-2014-3219 | fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.… | HIGH | 7.8 | Feb 9, 2018 |
| CVE-2014-2905 | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socke… | MEDIUM | 6.9 | May 2, 2014 |
Showing 1 to 7 of 7 CVEs