Записи Fujitsu
81 опубликованных записей вендора fujitsu.
Профиль для исследователя
- Попали в KEV
- 1 · 1,2 %
- С эксплойтом
- 2 · 2,5 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 19,8 %
- Медиана: публикация → KEV
- 3171 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-287 Improper Authentication3
- CWE-312 Cleartext Storage of Sensitive Information3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
81 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2013-2251Готовый эксплойт | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2013 г. |
48В плане | CVE-2013-2566Готовый эксплойт | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to oracle · communications application session controller · CWE-326 | Средняя5,9 | — | 84,4 % | 15 мар. 2013 г. |
45В плане | CVE-2021-23840Proof of concept | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | Высокая7,5 | — | 50,7 % | 16 февр. 2021 г. |
42В плане | CVE-2016-8610Proof of concept | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processiopenssl · openssl · CWE-400 | Высокая7,5 | — | 39,7 % | 13 нояб. 2017 г. |
42В плане | CVE-2009-0270Эксплойта нет | Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to executfujitsu · systemcastwizard lite · CWE-119 | Критическая10,0 | — | 5,5 % | 26 янв. 2009 г. |
41В плане | CVE-2018-1000007Эксплойта нет | libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties.haxx · curl | Критическая9,8 | — | 8,0 % | 24 янв. 2018 г. |
41В плане | CVE-2008-1040Эксплойта нет | Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0fujitsu · interstage application server enterprise · CWE-119 | Критическая10,0 | — | 4,6 % | 27 февр. 2008 г. |
41В плане | CVE-2013-7105Эксплойта нет | Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1fujitsu · interstage application server · CWE-119 | Критическая10,0 | — | 1,8 % | 14 дек. 2013 г. |
40В плане | CVE-2019-6111Proof of concept | An issue was discovered in OpenSSH 7.9.openbsd · openssh · CWE-22 | Средняя5,9 | — | 58,2 % | 31 янв. 2019 г. |
40В плане | CVE-2020-29127Эксплойта нет | An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25.fujitsu · eternus storage dx200 s4 firmware · CWE-287 | Критическая9,8 | — | 4,5 % | 30 нояб. 2020 г. |
40В плане | CVE-2022-31794Эксплойта нет | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.fujitsu · eternus cs8000 firmware · CWE-78 | Критическая9,8 | — | 3,1 % | 20 июн. 2022 г. |
40В плане | CVE-2022-31795Эксплойта нет | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.fujitsu · eternus cs8000 firmware · CWE-78 | Критическая9,8 | — | 3,1 % | 20 июн. 2022 г. |
40В плане | CVE-2019-18200Эксплойта нет | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices.fujitsu · lx390 firmware | Критическая9,8 | — | 2,8 % | 24 окт. 2019 г. |
40В плане | CVE-2022-29516Эксплойта нет | The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), Ifujitsu · ipcom ex2 nw 1100 firmware · CWE-78 | Критическая9,8 | — | 2,2 % | 18 мая 2022 г. |
40В плане | CVE-2009-0264Эксплойта нет | Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectfujitsu · systemcastwizard lite · CWE-119 | Критическая10,0 | — | 1,6 % | 26 янв. 2009 г. |
39Наблюдать | CVE-2023-4092Эксплойта нет | SQL injection vulnerability in Fujitsu Arconte Áureafujitsu · arconte aurea · CWE-89 | Критическая9,8 | — | 0,7 % | 19 сент. 2023 г. |
38Наблюдать | CVE-2019-9835Эксплойта нет | The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection.fujitsu · lx901 firmware | Критическая9,6 | — | 0,6 % | 15 мар. 2019 г. |
36Наблюдать | CVE-2015-2808Эксплойта нет | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initializatiooracle · communications application session controller · CWE-327 | Низкая3,7 | — | 73,9 % | 31 мар. 2015 г. |
35Наблюдать | CVE-2023-38555Эксплойта нет | Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attackefujitsu · si-r 30b firmware · CWE-287 | Высокая8,8 | — | 0,4 % | 26 июл. 2023 г. |
34Наблюдать | CVE-2024-33620Эксплойта нет | Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR.fsas technologies inc. · fujitsu business application id link manager ii · CWE-36 | Высокая8,6 | — | 0,7 % | 18 июн. 2024 г. |
33Наблюдать | CVE-2020-8285Эксплойта нет | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.haxx · libcurl · CWE-674 | Высокая7,5 | — | 9,8 % | 14 дек. 2020 г. |
32Наблюдать | CVE-2018-16156Proof of concept | In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messafujitsu · paperstream ip \(twain\) · CWE-426 | Высокая7,8 | — | 2,6 % | 17 мая 2019 г. |
32Наблюдать | CVE-2023-4094Эксплойта нет | Weak authentication vulnerability in Fujitsu Arconte Áureafujitsu · arconte aurea · CWE-1390 | Высокая8,2 | — | 0,5 % | 19 сент. 2023 г. |
32Наблюдать | CVE-2023-4096Эксплойта нет | Weak password recovery mechanism vulnerability in Fujitsu Arconte Áureafujitsu · arconte aurea · CWE-640 | Высокая8,2 | — | 0,4 % | 19 сент. 2023 г. |
31Наблюдать | CVE-2007-3011Proof of concept | The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute fujitsu · serverview | Высокая7,5 | — | 4,2 % | 5 июл. 2007 г. |
- CVE-2013-225199Срочно
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · archiva19 июл. 2013 г.
- CVE-2013-256648В плане
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to
СредняяCVSS 5,9Готовый эксплойтEPSS 84 %oracle · communications application session controller15 мар. 2013 г.
- CVE-2021-2384045В плане
Integer overflow in CipherUpdate
ВысокаяCVSS 7,5Proof of conceptEPSS 51 %openssl · openssl16 февр. 2021 г.
- CVE-2016-861042В плане
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processi
ВысокаяCVSS 7,5Proof of conceptEPSS 40 %openssl · openssl13 нояб. 2017 г.
- CVE-2009-027042В плане
Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execut
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %fujitsu · systemcastwizard lite26 янв. 2009 г.
- CVE-2018-100000741В плане
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %haxx · curl24 янв. 2018 г.
- CVE-2008-104041В плане
Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %fujitsu · interstage application server enterprise27 февр. 2008 г.
- CVE-2013-710541В плане
Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %fujitsu · interstage application server14 дек. 2013 г.
- CVE-2019-611140В плане
An issue was discovered in OpenSSH 7.9.
СредняяCVSS 5,9Proof of conceptEPSS 58 %openbsd · openssh31 янв. 2019 г.
- CVE-2020-2912740В плане
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %fujitsu · eternus storage dx200 s4 firmware30 нояб. 2020 г.
- CVE-2022-3179440В плане
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %fujitsu · eternus cs8000 firmware20 июн. 2022 г.
- CVE-2022-3179540В плане
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %fujitsu · eternus cs8000 firmware20 июн. 2022 г.
- CVE-2019-1820040В плане
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %fujitsu · lx390 firmware24 окт. 2019 г.
- CVE-2022-2951640В плане
The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), I
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fujitsu · ipcom ex2 nw 1100 firmware18 мая 2022 г.
- CVE-2009-026440В плане
Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vect
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %fujitsu · systemcastwizard lite26 янв. 2009 г.
- CVE-2023-409239Наблюдать
SQL injection vulnerability in Fujitsu Arconte Áurea
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %fujitsu · arconte aurea19 сент. 2023 г.
- CVE-2019-983538Наблюдать
The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection.
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %fujitsu · lx901 firmware15 мар. 2019 г.
- CVE-2015-280836Наблюдать
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initializatio
НизкаяCVSS 3,7Эксплойта нетEPSS 74 %oracle · communications application session controller31 мар. 2015 г.
- CVE-2023-3855535Наблюдать
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacke
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %fujitsu · si-r 30b firmware26 июл. 2023 г.
- CVE-2024-3362034Наблюдать
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %fsas technologies inc. · fujitsu business application id link manager ii18 июн. 2024 г.
- CVE-2020-828533Наблюдать
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %haxx · libcurl14 дек. 2020 г.
- CVE-2018-1615632Наблюдать
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messa
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %fujitsu · paperstream ip \(twain\)17 мая 2019 г.
- CVE-2023-409432Наблюдать
Weak authentication vulnerability in Fujitsu Arconte Áurea
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %fujitsu · arconte aurea19 сент. 2023 г.
- CVE-2023-409632Наблюдать
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %fujitsu · arconte aurea19 сент. 2023 г.
- CVE-2007-301131Наблюдать
The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %fujitsu · serverview5 июл. 2007 г.