CWE-254 · 379 записей
7PK - Security Features
CVE этого класса
379 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
56В плане | CVE-2016-2296Готовый эксплойт | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remmeteocontrol · web\'log basic 100 · CWE-254 | Критическая9,4 | — | 64,3 % | 14 мая 2016 г. |
49В плане | CVE-2015-1158Proof of concept | The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-cups · cups · CWE-254 | Критическая10,0 | — | 29,9 % | 26 июн. 2015 г. |
47В плане | CVE-2016-0161Эксплойта нет | Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege microsoft · edge · CWE-254 | Средняя6,5 | — | 68,8 % | 12 апр. 2016 г. |
45В плане | CVE-2015-1793Готовый эксплойт | The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic openssl · openssl · CWE-254 | Средняя6,5 | — | 62,4 % | 9 июл. 2015 г. |
43В плане | CVE-2016-3238Proof of concept | The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201microsoft · windows 10 · CWE-254 | Высокая8,1 | — | 35,4 % | 12 июл. 2016 г. |
41В плане | CVE-2016-2118Proof of concept | The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCsamba · samba · CWE-254 | Высокая7,5 | — | 36,9 % | 12 апр. 2016 г. |
41В плане | CVE-2016-10178Эксплойта нет | An issue was discovered on the D-Link DWR-932B router.dlink · dwr-932b firmware · CWE-254 | Критическая9,8 | — | 7,3 % | 30 янв. 2017 г. |
41В плане | CVE-2016-6957Эксплойта нет | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continadobe · acrobat · CWE-254 | Критическая9,8 | — | 5,8 % | 13 окт. 2016 г. |
41В плане | CVE-2016-4215Эксплойта нет | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continadobe · acrobat · CWE-254 | Критическая9,8 | — | 5,7 % | 12 июл. 2016 г. |
41В плане | CVE-2014-5334Эксплойта нет | FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.freenas · freenas · CWE-254 | Критическая9,8 | — | 5,1 % | 8 янв. 2018 г. |
41В плане | CVE-2015-3972Эксплойта нет | The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easiejanitza · umg 508 · CWE-254 | Критическая10,0 | — | 2,9 % | 28 окт. 2015 г. |
41В плане | CVE-2016-5788Эксплойта нет | General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it ge · bently nevada 3500\/22m usb firmware · CWE-254 | Критическая10,0 | — | 2,3 % | 24 нояб. 2016 г. |
40В плане | CVE-2015-8286Эксплойта нет | Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP porzhuhai · raysharp firmware · CWE-254 | Критическая9,8 | — | 4,6 % | 18 февр. 2016 г. |
40В плане | CVE-2015-8803Эксплойта нет | The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its nettle project · nettle · CWE-254 | Критическая9,8 | — | 4,2 % | 23 февр. 2016 г. |
40В плане | CVE-2015-7554Эксплойта нет | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or libtiff · libtiff · CWE-254 | Критическая9,8 | — | 4,2 % | 8 янв. 2016 г. |
40В плане | CVE-2017-8227Эксплойта нет | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are deamcrest · ipm-721s firmware · CWE-254 | Критическая9,8 | — | 4,1 % | 3 июл. 2019 г. |
40В плане | CVE-2015-8804Эксплойта нет | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation nettle project · nettle · CWE-254 | Критическая9,8 | — | 3,9 % | 23 февр. 2016 г. |
40В плане | CVE-2015-8857Эксплойта нет | The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which muglifyjs project · uglifyjs · CWE-254 | Критическая9,8 | — | 3,6 % | 23 янв. 2017 г. |
40В плане | CVE-2015-6473Эксплойта нет | WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.wago · 750-849 firmware · CWE-254 | Критическая9,8 | — | 3,5 % | 22 авг. 2017 г. |
40В плане | CVE-2016-1896Эксплойта нет | Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0lexmark · printer firmware · CWE-254 | Критическая9,8 | — | 3,3 % | 27 янв. 2016 г. |
40В плане | CVE-2016-6629Эксплойта нет | An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive.phpmyadmin · phpmyadmin · CWE-254 | Критическая9,8 | — | 3,2 % | 10 дек. 2016 г. |
40В плане | CVE-2011-4889Эксплойта нет | The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before ibm · websphere application server · CWE-254 | Критическая9,8 | — | 2,7 % | 8 февр. 2018 г. |
40В плане | CVE-2016-10321Эксплойта нет | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-forweb2py · web2py · CWE-254 | Критическая9,8 | — | 2,6 % | 10 апр. 2017 г. |
40В плане | CVE-2016-0332Эксплойта нет | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed libm · security identity manager virtual appliance · CWE-254 | Критическая9,8 | — | 2,3 % | 12 янв. 2018 г. |
40В плане | CVE-2016-9865Эксплойта нет | An issue was discovered in phpMyAdmin.phpmyadmin · phpmyadmin · CWE-254 | Критическая9,8 | — | 2,3 % | 10 дек. 2016 г. |
- CVE-2016-229656В плане
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows rem
КритическаяCVSS 9,4Готовый эксплойтEPSS 64 %meteocontrol · web\'log basic 10014 мая 2016 г.
- CVE-2015-115849В плане
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-
КритическаяCVSS 10,0Proof of conceptEPSS 30 %cups · cups26 июн. 2015 г.
- CVE-2016-016147В плане
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege
СредняяCVSS 6,5Эксплойта нетEPSS 69 %microsoft · edge12 апр. 2016 г.
- CVE-2015-179345В плане
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic
СредняяCVSS 6,5Готовый эксплойтEPSS 62 %openssl · openssl9 июл. 2015 г.
- CVE-2016-323843В плане
The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201
ВысокаяCVSS 8,1Proof of conceptEPSS 35 %microsoft · windows 1012 июл. 2016 г.
- CVE-2016-211841В плане
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DC
ВысокаяCVSS 7,5Proof of conceptEPSS 37 %samba · samba12 апр. 2016 г.
- CVE-2016-1017841В плане
An issue was discovered on the D-Link DWR-932B router.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %dlink · dwr-932b firmware30 янв. 2017 г.
- CVE-2016-695741В плане
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Contin
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %adobe · acrobat13 окт. 2016 г.
- CVE-2016-421541В плане
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Contin
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %adobe · acrobat12 июл. 2016 г.
- CVE-2014-533441В плане
FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %freenas · freenas8 янв. 2018 г.
- CVE-2015-397241В плане
The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easie
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %janitza · umg 50828 окт. 2015 г.
- CVE-2016-578841В плане
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %ge · bently nevada 3500\/22m usb firmware24 нояб. 2016 г.
- CVE-2015-828640В плане
Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP por
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %zhuhai · raysharp firmware18 февр. 2016 г.
- CVE-2015-880340В плане
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nettle project · nettle23 февр. 2016 г.
- CVE-2015-755440В плане
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libtiff · libtiff8 янв. 2016 г.
- CVE-2017-822740В плане
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are de
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %amcrest · ipm-721s firmware3 июл. 2019 г.
- CVE-2015-880440В плане
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nettle project · nettle23 февр. 2016 г.
- CVE-2015-885740В плане
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which m
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %uglifyjs project · uglifyjs23 янв. 2017 г.
- CVE-2015-647340В плане
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %wago · 750-849 firmware22 авг. 2017 г.
- CVE-2016-189640В плане
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lexmark · printer firmware27 янв. 2016 г.
- CVE-2016-662940В плане
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phpmyadmin · phpmyadmin10 дек. 2016 г.
- CVE-2011-488940В плане
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ibm · websphere application server8 февр. 2018 г.
- CVE-2016-1032140В плане
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %web2py · web2py10 апр. 2017 г.
- CVE-2016-033240В плане
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed l
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ibm · security identity manager virtual appliance12 янв. 2018 г.
- CVE-2016-986540В плане
An issue was discovered in phpMyAdmin.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpmyadmin · phpmyadmin10 дек. 2016 г.