gluster kayıtları
gluster üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation6
- CWE-400 Uncontrolled Resource Consumption2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-476 NULL Pointer Dereference2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-121 Stack-based Buffer Overflow1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2018-10907İstismar yok | It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fgluster · glusterfs · CWE-121 | Yüksek8,8 | — | %3,4 | 4 Eyl 2018 |
36İzleyin | CVE-2018-10929İstismar yok | A flaw was found in RPC request using gfs2_create_req in glusterfs server.gluster · glusterfs · CWE-20 | Yüksek8,8 | — | %3,3 | 4 Eyl 2018 |
36İzleyin | CVE-2018-14651İstismar yok | It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete.debian · debian linux · CWE-59 | Yüksek8,8 | — | %3,2 | 31 Eki 2018 |
36İzleyin | CVE-2018-10904İstismar yok | It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by gluster · glusterfs · CWE-426 | Yüksek8,8 | — | %3,0 | 4 Eyl 2018 |
36İzleyin | CVE-2018-10928İstismar yok | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside gluster · glusterfs · CWE-59 | Yüksek8,8 | — | %2,7 | 4 Eyl 2018 |
36İzleyin | CVE-2018-10926İstismar yok | A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server.gluster · glusterfs · CWE-20 | Yüksek8,8 | — | %2,6 | 4 Eyl 2018 |
36İzleyin | CVE-2018-1112İstismar yok | glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster clientgluster · glusterfs · CWE-287 | Yüksek8,8 | — | %2,4 | 25 Nis 2018 |
35İzleyin | CVE-2018-10841İstismar yok | glusterfs is vulnerable to privilege escalation on gluster server nodes.gluster · glusterfs · CWE-288 | Yüksek8,8 | — | %1,3 | 20 Haz 2018 |
33İzleyin | CVE-2018-10927İstismar yok | A flaw was found in RPC request using gfs3_lookup_req in glusterfs server.gluster · glusterfs · CWE-20 | Yüksek8,1 | — | %2,8 | 4 Eyl 2018 |
33İzleyin | CVE-2018-10923İstismar yok | It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node.gluster · glusterfs · CWE-20 | Yüksek8,1 | — | %1,7 | 4 Eyl 2018 |
31İzleyin | CVE-2018-10911İstismar yok | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values.gluster · glusterfs · CWE-190 | Yüksek7,5 | — | %3,1 | 4 Eyl 2018 |
30İzleyin | CVE-2023-26253İstismar yok | In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.gluster · glusterfs · CWE-125 | Yüksek7,5 | — | %0,9 | 20 Şub 2023 |
30İzleyin | CVE-2022-48340İstismar yok | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.gluster · glusterfs · CWE-416 | Yüksek7,5 | — | %0,9 | 20 Şub 2023 |
27İzleyin | CVE-2018-14661İstismar yok | It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage,gluster · glusterfs · CWE-20 | Orta6,5 | — | %2,7 | 31 Eki 2018 |
27İzleyin | CVE-2018-14660İstismar yok | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr.gluster · glusterfs · CWE-400 | Orta6,5 | — | %2,5 | 1 Kas 2018 |
27İzleyin | CVE-2018-10914İstismar yok | It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a gluster · glusterfs · CWE-476 | Orta6,5 | — | %2,4 | 4 Eyl 2018 |
27İzleyin | CVE-2018-10930İstismar yok | A flaw was found in RPC request using gfs3_rename_req in glusterfs server.gluster · glusterfs · CWE-20 | Orta6,5 | — | %2,1 | 4 Eyl 2018 |
27İzleyin | CVE-2018-10913İstismar yok | An information disclosure vulnerability was discovered in glusterfs server.gluster · glusterfs · CWE-209 | Orta6,5 | — | %2,1 | 4 Eyl 2018 |
27İzleyin | CVE-2018-10924İstismar yok | It was discovered that fsync(2) system call in glusterfs client code leaks memory.gluster · glusterfs · CWE-400 | Orta6,5 | — | %1,9 | 4 Eyl 2018 |
21İzleyin | CVE-2014-3619İstismar yok | The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000gluster · glusterfs · CWE-399 | Orta5,0 | — | %2,7 | 27 Mar 2015 |
14İzleyin | CVE-2012-4417İstismar yok | GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary figluster · glusterfs · CWE-264 | Düşük3,6 | — | %0,3 | 18 Kas 2012 |
13İzleyin | CVE-2017-15096İstismar yok | A flaw was found in GlusterFS in versions prior to 3.10.gluster · glusterfs · CWE-476 | Düşük3,3 | — | %0,3 | 26 Eki 2017 |
8İzleyin | CVE-2012-5635İstismar yok | The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitragluster · glusterfs · CWE-264 | Düşük2,1 | — | %0,3 | 9 Nis 2013 |
- CVE-2018-1090736İzleyin
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating f
YüksekCVSS 8,8İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2018-1092936İzleyin
A flaw was found in RPC request using gfs2_create_req in glusterfs server.
YüksekCVSS 8,8İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2018-1465136İzleyin
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete.
YüksekCVSS 8,8İstismar yokEPSS %3debian · debian linux31 Eki 2018
- CVE-2018-1090436İzleyin
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by
YüksekCVSS 8,8İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2018-1092836İzleyin
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside
YüksekCVSS 8,8İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2018-1092636İzleyin
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server.
YüksekCVSS 8,8İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2018-111236İzleyin
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client
YüksekCVSS 8,8İstismar yokEPSS %2gluster · glusterfs25 Nis 2018
- CVE-2018-1084135İzleyin
glusterfs is vulnerable to privilege escalation on gluster server nodes.
YüksekCVSS 8,8İstismar yokEPSS %1gluster · glusterfs20 Haz 2018
- CVE-2018-1092733İzleyin
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server.
YüksekCVSS 8,1İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2018-1092333İzleyin
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node.
YüksekCVSS 8,1İstismar yokEPSS %2gluster · glusterfs4 Eyl 2018
- CVE-2018-1091131İzleyin
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values.
YüksekCVSS 7,5İstismar yokEPSS %3gluster · glusterfs4 Eyl 2018
- CVE-2023-2625330İzleyin
In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.
YüksekCVSS 7,5İstismar yokEPSS %1gluster · glusterfs20 Şub 2023
- CVE-2022-4834030İzleyin
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
YüksekCVSS 7,5İstismar yokEPSS %1gluster · glusterfs20 Şub 2023
- CVE-2018-1466127İzleyin
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage,
OrtaCVSS 6,5İstismar yokEPSS %3gluster · glusterfs31 Eki 2018
- CVE-2018-1466027İzleyin
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr.
OrtaCVSS 6,5İstismar yokEPSS %3gluster · glusterfs1 Kas 2018
- CVE-2018-1091427İzleyin
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a
OrtaCVSS 6,5İstismar yokEPSS %2gluster · glusterfs4 Eyl 2018
- CVE-2018-1093027İzleyin
A flaw was found in RPC request using gfs3_rename_req in glusterfs server.
OrtaCVSS 6,5İstismar yokEPSS %2gluster · glusterfs4 Eyl 2018
- CVE-2018-1091327İzleyin
An information disclosure vulnerability was discovered in glusterfs server.
OrtaCVSS 6,5İstismar yokEPSS %2gluster · glusterfs4 Eyl 2018
- CVE-2018-1092427İzleyin
It was discovered that fsync(2) system call in glusterfs client code leaks memory.
OrtaCVSS 6,5İstismar yokEPSS %2gluster · glusterfs4 Eyl 2018
- CVE-2014-361921İzleyin
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000
OrtaCVSS 5,0İstismar yokEPSS %3gluster · glusterfs27 Mar 2015
- CVE-2012-441714İzleyin
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary fi
DüşükCVSS 3,6İstismar yokEPSS %0gluster · glusterfs18 Kas 2012
- CVE-2017-1509613İzleyin
A flaw was found in GlusterFS in versions prior to 3.10.
DüşükCVSS 3,3İstismar yokEPSS %0gluster · glusterfs26 Eki 2017
- CVE-2012-56358İzleyin
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitra
DüşükCVSS 2,1İstismar yokEPSS %0gluster · glusterfs9 Nis 2013