Записи fail2ban
9 опубликованных записей вендора fail2ban.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 88,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation3
- CWE-287 Improper Authentication1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2021-32749Эксплойта нет | Possible RCE vulnerability in mailing action using mailutils (mail-whois)fail2ban · fail2ban · CWE-78 | Высокая8,1 | — | 3,6 % | 16 июл. 2021 г. |
31Наблюдать | CVE-2012-5642Эксплойта нет | server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trifail2ban · fail2ban | Высокая7,5 | — | 3,1 % | 31 дек. 2012 г. |
29Наблюдать | CVE-2007-4321Proof of concept | fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.denyfail2ban · fail2ban | Средняя6,8 | — | 5,7 % | 13 авг. 2007 г. |
21Наблюдать | CVE-2013-7176Эксплойта нет | config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitraryfail2ban · fail2ban · CWE-20 | Средняя5,0 | — | 3,2 % | 1 февр. 2014 г. |
21Наблюдать | CVE-2013-7177Эксплойта нет | config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbfail2ban · fail2ban · CWE-20 | Средняя5,0 | — | 3,2 % | 1 февр. 2014 г. |
21Наблюдать | CVE-2006-6302Эксплойта нет | fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.defail2ban · fail2ban | Средняя5,0 | — | 1,8 % | 6 дек. 2006 г. |
21Наблюдать | CVE-2013-2178Эксплойта нет | The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly vafail2ban · fail2ban · CWE-20 | Средняя5,0 | — | 1,8 % | 28 авг. 2013 г. |
18Наблюдать | CVE-2009-5023Эксплойта нет | The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8fail2ban · fail2ban · CWE-59 | Средняя4,7 | — | 0,3 % | 10 июн. 2014 г. |
16Наблюдать | CVE-2009-0362Эксплойта нет | filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forcefail2ban · fail2ban · CWE-287 | Средняя4,0 | — | 1,3 % | 12 февр. 2009 г. |
- CVE-2021-3274933Наблюдать
Possible RCE vulnerability in mailing action using mailutils (mail-whois)
ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %fail2ban · fail2ban16 июл. 2021 г.
- CVE-2012-564231Наблюдать
server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to tri
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %fail2ban · fail2ban31 дек. 2012 г.
- CVE-2007-432129Наблюдать
fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny
СредняяCVSS 6,8Proof of conceptEPSS 6 %fail2ban · fail2ban13 авг. 2007 г.
- CVE-2013-717621Наблюдать
config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary
СредняяCVSS 5,0Эксплойта нетEPSS 3 %fail2ban · fail2ban1 февр. 2014 г.
- CVE-2013-717721Наблюдать
config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arb
СредняяCVSS 5,0Эксплойта нетEPSS 3 %fail2ban · fail2ban1 февр. 2014 г.
- CVE-2006-630221Наблюдать
fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.de
СредняяCVSS 5,0Эксплойта нетEPSS 2 %fail2ban · fail2ban6 дек. 2006 г.
- CVE-2013-217821Наблюдать
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly va
СредняяCVSS 5,0Эксплойта нетEPSS 2 %fail2ban · fail2ban28 авг. 2013 г.
- CVE-2009-502318Наблюдать
The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8
СредняяCVSS 4,7Эксплойта нетEPSS 0 %fail2ban · fail2ban10 июн. 2014 г.
- CVE-2009-036216Наблюдать
filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (force
СредняяCVSS 4,0Эксплойта нетEPSS 1 %fail2ban · fail2ban12 февр. 2009 г.