İçeriğe atla
Noroxi

Debian kayıtları

debian üreticisine ait 10.221 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
123 · %1,2
Silahlaştırılmış
201 · %2
Pre-auth RCE
752
Düzeltme kaydı olan
%97,4
Yayından KEV’e ortanca
362 gün

Tüm kayıtlar

10.000+ kayıt
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99

    redis · redis18 Şub 2022

  • Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99

    erlang · erlang\/otp16 Nis 2025

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php11 May 2012

  • Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    drupal · drupal29 Mar 2018

  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    exim · exim5 Haz 2019

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · tomcat10 Mar 2025

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · activemq27 Eki 2023

  • Underflow in PHP-FPM can lead to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php28 Eki 2019

  • An issue was discovered in SaltStack Salt through 3002.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    saltstack · salt6 Kas 2020

  • Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    samba · samba30 May 2017

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    drupal · drupal19 Tem 2018

  • telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    gnu · inetutils21 Oca 2026

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    openbsd · opensmtpd29 Oca 2020

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    oracle · jre7 Haz 2012

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    saltstack · salt30 Nis 2020

  • Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    phpmyadmin · phpmyadmin26 Mar 2009

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    oracle · jdk21 Nis 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    resf · rocky linux16 Eyl 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    apache · log4j14 Ara 2021

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90

    apache · tomcat6 Nis 2017

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    google · chrome12 Eyl 2023