Записи erlang
46 опубликованных записей вендора erlang.
Профиль для исследователя
- Попали в KEV
- 1 · 2,2 %
- С эксплойтом
- 2 · 4,3 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 93,5 %
- Медиана: публикация → KEV
- 54 дн.
Повторяющиеся классы
- CWE-295 Improper Certificate Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-863 Incorrect Authorization2
- CWE-121 Stack-based Buffer Overflow2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
46 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2025-32433Готовый эксплойт | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Критическая10,0 | KEV | 98,8 % | 16 апр. 2025 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,3 % | 18 дек. 2023 г. |
41В плане | CVE-2020-13802Эксплойта нет | Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.erlang · rebar3 · CWE-78 | Критическая9,8 | — | 6,8 % | 2 сент. 2020 г. |
39Наблюдать | CVE-2016-10253Эксплойта нет | An issue was discovered in Erlang/OTP 18.x.erlang · erlang\/otp · CWE-119 | Критическая9,8 | — | 1,5 % | 18 мар. 2017 г. |
39Наблюдать | CVE-2022-37026Эксплойта нет | In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certerlang · erlang\/otp | Критическая9,8 | — | 1,5 % | 21 сент. 2022 г. |
36Наблюдать | CVE-2019-1000014Эксплойта нет | Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Paerlang · rebar3 | Высокая8,8 | — | 1,8 % | 4 февр. 2019 г. |
36Наблюдать | CVE-2026-55953Эксплойта нет | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationerlang · erlang\/otp · CWE-757 | Критическая9,1 | — | 0,4 % | 27 июл. 2026 г. |
35Наблюдать | CVE-2026-49759Эксплойта нет | Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crasherlang · erlang\/otp · CWE-121 | Высокая8,8 | — | 0,9 % | 10 июн. 2026 г. |
34Наблюдать | CVE-2026-55950Эксплойта нет | DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionserlang · erlang\/otp · CWE-367 | Высокая8,7 | — | 0,7 % | 2 июл. 2026 г. |
34Наблюдать | CVE-2026-58227Эксплойта нет | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainerlang · erlang\/otp · CWE-674 | Высокая8,7 | — | 0,7 % | 27 июл. 2026 г. |
34Наблюдать | CVE-2026-59251Эксплойта нет | Denial of service via exponential certificate policy tree growth in path validationerlang · erlang\/otp · CWE-770 | Высокая8,7 | — | 0,5 % | 27 июл. 2026 г. |
33Наблюдать | CVE-2026-28808Эксплойта нет | ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)erlang · erlang\/inets · CWE-863 | Высокая8,3 | — | 0,8 % | 7 апр. 2026 г. |
32Наблюдать | CVE-2011-0766Эксплойта нет | The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14erlang · crypto · CWE-310 | Высокая7,8 | — | 3,1 % | 31 мая 2011 г. |
32Наблюдать | CVE-2026-55952Эксплойта нет | TLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionerlang · erlang\/otp · CWE-1284 | Высокая8,2 | — | 0,9 % | 2 июл. 2026 г. |
32Наблюдать | CVE-2026-54890Эксплойта нет | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingerlang · erlang\/otp · CWE-191 | Высокая8,2 | — | 0,7 % | 27 июл. 2026 г. |
31Наблюдать | CVE-2020-25623Эксплойта нет | Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.erlang · erlang\/otp · CWE-22 | Высокая7,5 | — | 3,2 % | 2 окт. 2020 г. |
31Наблюдать | CVE-2014-1693Эксплойта нет | Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP comerlang · erlang\/otp | Высокая7,5 | — | 2,2 % | 8 дек. 2014 г. |
30Наблюдать | CVE-2017-1000385Готовый эксплойт | The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding.erlang · erlang\/otp · CWE-203 | Средняя5,9 | — | 22,1 % | 12 дек. 2017 г. |
30Наблюдать | CVE-2009-0130Эксплойта нет | lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow erlang · erlang · CWE-287 | Высокая7,5 | — | 1,2 % | 15 янв. 2009 г. |
30Наблюдать | CVE-2020-35733Эксплойта нет | An issue was discovered in Erlang/OTP before 23.2.2.erlang · erlang\/otp · CWE-295 | Высокая7,5 | — | 1,2 % | 15 янв. 2021 г. |
30Наблюдать | CVE-2026-42790Эксплойта нет | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationerlang · erlang\/otp · CWE-295 | Высокая7,6 | — | 0,5 % | 27 мая 2026 г. |
30Наблюдать | CVE-2026-48860Эксплойта нет | Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_disterlang · erlang\/otp · CWE-863 | Высокая7,5 | — | 0,4 % | 10 июн. 2026 г. |
30Наблюдать | CVE-2026-32144Эксплойта нет | OCSP designated-responder authorization bypass via missing signature verificationerlang · erlang\/otp · CWE-295 | Высокая7,6 | — | 0,3 % | 7 апр. 2026 г. |
28Наблюдать | CVE-2021-29221Эксплойта нет | A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3.erlang · erlang\/otp · CWE-426 | Высокая7,0 | — | 0,6 % | 9 апр. 2021 г. |
28Наблюдать | CVE-2026-48856Эксплойта нет | httpc leaks Authorization header to cross-origin redirect targetserlang · erlang\/inets · CWE-601 | Высокая7,1 | — | 0,6 % | 10 июн. 2026 г. |
- CVE-2025-32433100Срочно
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %erlang · erlang\/otp16 апр. 2025 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 93 %ssh · ssh18 дек. 2023 г.
- CVE-2020-1380241В плане
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %erlang · rebar32 сент. 2020 г.
- CVE-2016-1025339Наблюдать
An issue was discovered in Erlang/OTP 18.x.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %erlang · erlang\/otp18 мар. 2017 г.
- CVE-2022-3702639Наблюдать
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-cert
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %erlang · erlang\/otp21 сент. 2022 г.
- CVE-2019-100001436Наблюдать
Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Pa
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %erlang · rebar34 февр. 2019 г.
- CVE-2026-5595336Наблюдать
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %erlang · erlang\/otp27 июл. 2026 г.
- CVE-2026-4975935Наблюдать
Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %erlang · erlang\/otp10 июн. 2026 г.
- CVE-2026-5595034Наблюдать
DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %erlang · erlang\/otp2 июл. 2026 г.
- CVE-2026-5822734Наблюдать
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %erlang · erlang\/otp27 июл. 2026 г.
- CVE-2026-5925134Наблюдать
Denial of service via exponential certificate policy tree growth in path validation
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %erlang · erlang\/otp27 июл. 2026 г.
- CVE-2026-2880833Наблюдать
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %erlang · erlang\/inets7 апр. 2026 г.
- CVE-2011-076632Наблюдать
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %erlang · crypto31 мая 2011 г.
- CVE-2026-5595232Наблюдать
TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %erlang · erlang\/otp2 июл. 2026 г.
- CVE-2026-5489032Наблюдать
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %erlang · erlang\/otp27 июл. 2026 г.
- CVE-2020-2562331Наблюдать
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %erlang · erlang\/otp2 окт. 2020 г.
- CVE-2014-169331Наблюдать
Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP com
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %erlang · erlang\/otp8 дек. 2014 г.
- CVE-2017-100038530Наблюдать
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding.
СредняяCVSS 5,9Готовый эксплойтEPSS 22 %erlang · erlang\/otp12 дек. 2017 г.
- CVE-2009-013030Наблюдать
lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %erlang · erlang15 янв. 2009 г.
- CVE-2020-3573330Наблюдать
An issue was discovered in Erlang/OTP before 23.2.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %erlang · erlang\/otp15 янв. 2021 г.
- CVE-2026-4279030Наблюдать
nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %erlang · erlang\/otp27 мая 2026 г.
- CVE-2026-4886030Наблюдать
Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %erlang · erlang\/otp10 июн. 2026 г.
- CVE-2026-3214430Наблюдать
OCSP designated-responder authorization bypass via missing signature verification
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %erlang · erlang\/otp7 апр. 2026 г.
- CVE-2021-2922128Наблюдать
A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3.
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %erlang · erlang\/otp9 апр. 2021 г.
- CVE-2026-4885628Наблюдать
httpc leaks Authorization header to cross-origin redirect targets
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %erlang · erlang\/inets10 июн. 2026 г.