bareos records
6 published records for vendor bareos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-122 Heap-based Buffer Overflow1
- CWE-285 Improper Authorization1
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-665 Improper Initialization1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-24755No exploit | Incorrect Authorization in Bareos Directorbareos · bareos · CWE-863 | Critical9.8 | — | 2.0% | Mar 15, 2022 |
35Monitor | CVE-2024-45044No exploit | Bareos's negative command ACLs can be circumvented by abbreviating commandsbareos · bareos · CWE-285 | High8.8 | — | 0.5% | Sep 10, 2024 |
31Monitor | CVE-2022-24756No exploit | Missing Release of Memory after Effective Lifetime in Bareos Directorbareos · bareos · CWE-401 | High7.5 | — | 1.9% | Mar 15, 2022 |
31Monitor | CVE-2017-14610No exploit | bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root abareos · bareos · CWE-665 | High7.8 | — | 0.3% | Sep 20, 2017 |
29Monitor | CVE-2020-11061No exploit | Heap-based Buffer Overflow in Bareos Directorbareos · bareos · CWE-122 | High7.4 | — | 1.2% | Jul 10, 2020 |
27Monitor | CVE-2020-4042No exploit | Authentication bypass in Bareosbareos · bareos · CWE-294 | Medium6.8 | — | 1.0% | Jul 10, 2020 |
- CVE-2022-2475540Plan
Incorrect Authorization in Bareos Director
CriticalCVSS 9.8No exploitEPSS 2%bareos · bareosMar 15, 2022
- CVE-2024-4504435Monitor
Bareos's negative command ACLs can be circumvented by abbreviating commands
HighCVSS 8.8No exploitEPSS 1%bareos · bareosSep 10, 2024
- CVE-2022-2475631Monitor
Missing Release of Memory after Effective Lifetime in Bareos Director
HighCVSS 7.5No exploitEPSS 2%bareos · bareosMar 15, 2022
- CVE-2017-1461031Monitor
bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root a
HighCVSS 7.8No exploitEPSS 0%bareos · bareosSep 20, 2017
- CVE-2020-1106129Monitor
Heap-based Buffer Overflow in Bareos Director
HighCVSS 7.4No exploitEPSS 1%bareos · bareosJul 10, 2020
- CVE-2020-404227Monitor
Authentication bypass in Bareos
MediumCVSS 6.8No exploitEPSS 1%bareos · bareosJul 10, 2020