Apple kayıtları
apple üreticisine ait 15.437 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 167 · %1,1
- Silahlaştırılmış
- 243 · %1,6
- Pre-auth RCE
- 4.143
- Düzeltme kaydı olan
- %24,3
- Yayından KEV’e ortanca
- 234 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2.367
- CWE-416 Use After Free1.361
- CWE-125 Out-of-bounds Read1.353
- CWE-787 Out-of-bounds Write1.275
- CWE-20 Improper Input Validation825
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor746
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10.000+ kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2015-3113Silahlaştırılmış | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Kritik9,8 | KEV | %99,9 | 23 Haz 2015 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
99Hemen | CVE-2014-0497Silahlaştırılmış | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Kritik9,8 | KEV | %99,9 | 5 Şub 2014 |
99Hemen | CVE-2015-5119Silahlaştırılmış | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Kritik9,8 | KEV | %99,3 | 8 Tem 2015 |
98Hemen | CVE-2015-0313Silahlaştırılmış | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Kritik9,8 | KEV | %95,3 | 2 Şub 2015 |
97Hemen | CVE-2015-5122Silahlaştırılmış | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Kritik9,8 | KEV | %94,0 | 14 Tem 2015 |
97Hemen | CVE-2013-0625Silahlaştırılmış | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Kritik9,8 | KEV | %93,8 | 8 Oca 2013 |
96Hemen | CVE-2011-2462Silahlaştırılmış | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Kritik9,8 | KEV | %88,5 | 7 Ara 2011 |
95Hemen | CVE-2011-0611Silahlaştırılmış | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Yüksek8,8 | KEV | %99,4 | 13 Nis 2011 |
95Hemen | CVE-2015-0311Silahlaştırılmış | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Kritik9,8 | KEV | %85,6 | 23 Oca 2015 |
91Hemen | CVE-2021-21017Silahlaştırılmış | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Executionadobe · acrobat · CWE-122 | Yüksek8,8 | KEV | %86,3 | 11 Şub 2021 |
91Hemen | CVE-2015-3043Silahlaştırılmış | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Kritik9,8 | KEV | %73,9 | 14 Nis 2015 |
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
90Hemen | CVE-2009-3953Silahlaştırılmış | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | Yüksek8,8 | KEV | %83,2 | 13 Oca 2010 |
89Hemen | CVE-2012-0754Silahlaştırılmış | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.xadobe · flash player · CWE-787 | Yüksek8,1 | KEV | %91,2 | 16 Şub 2012 |
88Hemen | CVE-2018-15982Silahlaştırılmış | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.adobe · flash player · CWE-416 | Yüksek7,8 | KEV | %89,6 | 18 Oca 2019 |
88Hemen | CVE-2018-4878Silahlaştırılmış | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.adobe · flash player · CWE-416 | Yüksek7,8 | KEV | %89,5 | 6 Şub 2018 |
87Hemen | CVE-2013-0640Silahlaştırılmış | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | Yüksek7,8 | KEV | %86,9 | 13 Şub 2013 |
86Hemen | CVE-2010-1297Silahlaştırılmış | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,adobe · air · CWE-787 | Yüksek7,8 | KEV | %82,5 | 8 Haz 2010 |
86Hemen | CVE-2009-4324Silahlaştırılmış | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | Yüksek7,8 | KEV | %81,9 | 14 Ara 2009 |
86Hemen | CVE-2022-2294Silahlaştırılmış | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption viagoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %70,5 | 27 Tem 2022 |
85Hemen | CVE-2015-8651Silahlaştırılmış | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | Yüksek8,8 | KEV | %67,7 | 28 Ara 2015 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2015-311399Hemen
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player23 Haz 2015
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-049799Hemen
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player5 Şub 2014
- CVE-2015-511999Hemen
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99adobe · flash player8 Tem 2015
- CVE-2015-031398Hemen
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95adobe · flash player2 Şub 2015
- CVE-2015-512297Hemen
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · flash player14 Tem 2015
- CVE-2013-062597Hemen
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · coldfusion8 Oca 2013
- CVE-2011-246296Hemen
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %89adobe · acrobat7 Ara 2011
- CVE-2011-061195Hemen
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99adobe · flash player13 Nis 2011
- CVE-2015-031195Hemen
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86adobe · flash player23 Oca 2015
- CVE-2021-2101791Hemen
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %86adobe · acrobat11 Şub 2021
- CVE-2015-304391Hemen
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %74adobe · flash player14 Nis 2015
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2009-395390Hemen
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %83adobe · acrobat13 Oca 2010
- CVE-2012-075489Hemen
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %91adobe · flash player16 Şub 2012
- CVE-2018-1598288Hemen
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %90adobe · flash player18 Oca 2019
- CVE-2018-487888Hemen
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %90adobe · flash player6 Şub 2018
- CVE-2013-064087Hemen
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %87adobe · acrobat13 Şub 2013
- CVE-2010-129786Hemen
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %83adobe · air8 Haz 2010
- CVE-2009-432486Hemen
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %82adobe · acrobat14 Ara 2009
- CVE-2022-229486Hemen
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %70google · chrome27 Tem 2022
- CVE-2015-865185Hemen
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %68adobe · air sdk28 Ara 2015