İçeriğe atla
Noroxi

fedoraproject kayıtları

fedoraproject üreticisine ait 5.450 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
86 · %1,6
Silahlaştırılmış
115 · %2,1
Pre-auth RCE
332
Düzeltme kaydı olan
%92,7
Yayından KEV’e ortanca
148 gün

Tüm kayıtlar

5.450 kayıt
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php11 May 2012

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server5 Eki 2021

  • Argument Injection in PHP-CGI

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php9 Haz 2024

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server7 Eki 2021

  • Underflow in PHP-FPM can lead to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php28 Eki 2019

  • An issue was discovered in SaltStack Salt through 3002.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    saltstack · salt6 Kas 2020

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    openbsd · opensmtpd29 Oca 2020

  • OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    openslp · openslp6 Ara 2019

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    resf · rocky linux16 Eyl 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    apache · log4j14 Ara 2021

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    google · chrome12 Eyl 2023

  • XStream is vulnerable to a Remote Command Execution attack

    YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %98

    xstream · xstream23 Ağu 2021

  • Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing t

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    exiftool project · exiftool23 Nis 2021

  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    sudo project · sudo26 Oca 2021

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    openssl · openssl7 Nis 2014

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023

  • There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %99

    rubyonrails · rails27 Mar 2019

  • Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %84

    google · chrome26 Nis 2021

  • Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %70

    roundcube · webmail19 Kas 2021

  • Snapshot authentication bypass in grafana

    YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %100

    grafana · grafana5 Eki 2021

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93

    linux · linux kernel10 Mar 2022

  • Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %79

    google · chrome27 Şub 2020

  • Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %85

    php · archive tar19 Kas 2020