Debian kayıtları
debian üreticisine ait 10.221 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 123 · %1,2
- Silahlaştırılmış
- 201 · %2
- Pre-auth RCE
- 752
- Düzeltme kaydı olan
- %97,4
- Yayından KEV’e ortanca
- 362 gün
Tekrar eden sınıflar
- CWE-416 Use After Free732
- CWE-787 Out-of-bounds Write730
- CWE-125 Out-of-bounds Read685
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer539
- CWE-20 Improper Input Validation500
- CWE-476 NULL Pointer Dereference476
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10.000+ kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
100Hemen | CVE-2022-0543Silahlaştırılmış | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Kritik10,0 | KEV | %99,4 | 18 Şub 2022 |
100Hemen | CVE-2025-32433Silahlaştırılmış | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Kritik10,0 | KEV | %98,8 | 16 Nis 2025 |
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2018-7600Silahlaştırılmış | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Kritik9,8 | KEV | %100,0 | 29 Mar 2018 |
99Hemen | CVE-2019-10149Silahlaştırılmış | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Kritik9,8 | KEV | %100,0 | 5 Haz 2019 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
99Hemen | CVE-2025-24813Silahlaştırılmış | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Kritik9,8 | KEV | %99,9 | 10 Mar 2025 |
99Hemen | CVE-2023-46604Silahlaştırılmış | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Kritik9,8 | KEV | %99,9 | 27 Eki 2023 |
99Hemen | CVE-2019-11043Silahlaştırılmış | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Kritik9,8 | KEV | %99,8 | 28 Eki 2019 |
99Hemen | CVE-2020-16846Silahlaştırılmış | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Kritik9,8 | KEV | %99,6 | 6 Kas 2020 |
99Hemen | CVE-2017-7494Silahlaştırılmış | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Kritik9,8 | KEV | %99,4 | 30 May 2017 |
99Hemen | CVE-2020-1938Silahlaştırılmış | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Kritik9,8 | KEV | %99,3 | 24 Şub 2020 |
99Hemen | CVE-2018-7602Silahlaştırılmış | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Kritik9,8 | KEV | %99,2 | 19 Tem 2018 |
99Hemen | CVE-2026-24061Silahlaştırılmış | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.gnu · inetutils · CWE-88 | Kritik9,8 | KEV | %99,0 | 21 Oca 2026 |
99Hemen | CVE-2020-7247Silahlaştırılmış | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Kritik9,8 | KEV | %99,0 | 29 Oca 2020 |
98Hemen | CVE-2012-0507Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Kritik9,8 | KEV | %98,1 | 7 Haz 2012 |
98Hemen | CVE-2020-11651Silahlaştırılmış | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Kritik9,8 | KEV | %96,6 | 30 Nis 2020 |
98Hemen | CVE-2009-1151Silahlaştırılmış | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to injephpmyadmin · phpmyadmin · CWE-94 | Kritik9,8 | KEV | %96,6 | 26 Mar 2009 |
97Hemen | CVE-2016-3427Silahlaştırılmış | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Kritik9,8 | KEV | %92,3 | 21 Nis 2016 |
96Hemen | CVE-2021-40438Silahlaştırılmış | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Kritik9,0 | KEV | %100,0 | 16 Eyl 2021 |
96Hemen | CVE-2021-45046Silahlaştırılmış | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Kritik9,0 | KEV | %100,0 | 14 Ara 2021 |
96Hemen | CVE-2016-8735Silahlaştırılmış | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Kritik9,8 | KEV | %90,3 | 6 Nis 2017 |
95Hemen | CVE-2023-4863Silahlaştırılmış | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %100,0 | 12 Eyl 2023 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2022-0543100Hemen
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99redis · redis18 Şub 2022
- CVE-2025-32433100Hemen
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99erlang · erlang\/otp16 Nis 2025
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2018-760099Hemen
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100drupal · drupal29 Mar 2018
- CVE-2019-1014999Hemen
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100exim · exim5 Haz 2019
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2025-2481399Hemen
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · tomcat10 Mar 2025
- CVE-2023-4660499Hemen
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · activemq27 Eki 2023
- CVE-2019-1104399Hemen
Underflow in PHP-FPM can lead to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php28 Eki 2019
- CVE-2020-1684699Hemen
An issue was discovered in SaltStack Salt through 3002.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100saltstack · salt6 Kas 2020
- CVE-2017-749499Hemen
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99samba · samba30 May 2017
- CVE-2020-193899Hemen
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · geode24 Şub 2020
- CVE-2018-760299Hemen
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99drupal · drupal19 Tem 2018
- CVE-2026-2406199Hemen
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99gnu · inetutils21 Oca 2026
- CVE-2020-724799Hemen
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99openbsd · opensmtpd29 Oca 2020
- CVE-2012-050798Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98oracle · jre7 Haz 2012
- CVE-2020-1165198Hemen
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97saltstack · salt30 Nis 2020
- CVE-2009-115198Hemen
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97phpmyadmin · phpmyadmin26 Mar 2009
- CVE-2016-342797Hemen
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92oracle · jdk21 Nis 2016
- CVE-2021-4043896Hemen
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100resf · rocky linux16 Eyl 2021
- CVE-2021-4504696Hemen
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100apache · log4j14 Ara 2021
- CVE-2016-873596Hemen
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90apache · tomcat6 Nis 2017
- CVE-2023-486395Hemen
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100google · chrome12 Eyl 2023