Home/Product/elog project elog
Product

elog project elog

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-64349
<= 3.1.5-20251014
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then reque
8.8HIGH
CVE-2025-64348
<= 3.1.5-20251014
ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute fa
7.1HIGH
CVE-2025-62618
< 3.1.5-20251014
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when
8.0HIGH
CVE-2019-3996
<= 3.1.4-57bea22
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST
6.5MEDIUM
CVE-2019-3995
<= 3.1.4-57bea22
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthen
7.5HIGH
CVE-2019-3994
<= 3.1.4-57bea22
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated at
7.5HIGH
CVE-2019-3993
<= 3.1.4-57bea22
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover
7.5HIGH
CVE-2019-3992
<= 3.1.4-57bea22
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access
7.5HIGH
CVE-2016-6342
all versions
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
7.5HIGH
CVE-2008-7004
<= 2.7.0
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
CVE-2008-0445
all versions
The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of se
CVE-2008-0444
all versions
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web
CVE-2005-4439
all versions
Buffer overflow in ELOG elogd 2.6.0-beta4 allows remote attackers to cause a denial of service (application crash) and possibly ex
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin