Записи NSA
37 опубликованных записей вендора nsa.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 29,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-789 Memory Allocation with Excessive Size Value2
- CWE-416 Use After Free2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-502 Deserialization of Untrusted Data2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-16941Proof of concept | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Ensa · ghidra · CWE-91 | Критическая9,8 | — | 5,1 % | 28 сент. 2019 г. |
40В плане | CVE-2023-22671Эксплойта нет | Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injectionsa · ghidra · CWE-77 | Критическая9,8 | — | 2,9 % | 6 янв. 2023 г. |
39Наблюдать | CVE-2021-32639Эксплойта нет | Server-Side Request Forgery (SSRF) in emissary:emissarynsa · emissary · CWE-918 | Критическая9,9 | — | 1,4 % | 2 июл. 2021 г. |
37Наблюдать | CVE-2021-32647Эксплойта нет | Post-authentication Remote Code Execution (RCE) in emissary:emissarynsa · emissary · CWE-74 | Критическая9,1 | — | 2,9 % | 1 июн. 2021 г. |
37Наблюдать | CVE-2019-13625Эксплойта нет | NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.nsa · ghidra · CWE-611 | Критическая9,1 | — | 2,4 % | 16 июл. 2019 г. |
36Наблюдать | CVE-2026-35580Proof of concept | Emissary has GitHub Actions Shell Injection via Workflow Inputsnsa · emissary · CWE-77 | Критическая9,1 | — | 0,7 % | 7 апр. 2026 г. |
35Наблюдать | CVE-2021-32094Эксплойта нет | U.S.nsa · emissary · CWE-434 | Высокая8,8 | — | 1,2 % | 7 мая 2021 г. |
35Наблюдать | CVE-2026-35582Эксплойта нет | Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrixnsa · emissary · CWE-78 | Высокая8,8 | — | 1,1 % | 17 апр. 2026 г. |
35Наблюдать | CVE-2026-4946Эксплойта нет | NSA Ghidra Auto-Analysis Annotation Command Executionnsa · ghidra · CWE-78 | Высокая8,8 | — | 0,8 % | 29 мар. 2026 г. |
35Наблюдать | CVE-2021-32096Эксплойта нет | The ConsoleAction component of U.S.nsa · emissary · CWE-352 | Высокая8,8 | — | 0,6 % | 7 мая 2021 г. |
34Наблюдать | CVE-2026-52751Эксплойта нет | Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connectionnsa · ghidra · CWE-502 | Высокая8,6 | — | 1,1 % | 10 июн. 2026 г. |
34Наблюдать | CVE-2026-52758Эксплойта нет | Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Searchnsa · ghidra · CWE-89 | Высокая8,7 | — | 0,6 % | 10 июн. 2026 г. |
34Наблюдать | CVE-2026-49498Эксплойта нет | Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Usernamensa · ghidra · CWE-89 | Высокая8,7 | — | 0,5 % | 10 июн. 2026 г. |
34Наблюдать | CVE-2026-52754Эксплойта нет | Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModulensa · ghidra · CWE-347 | Высокая8,7 | — | 0,5 % | 10 июн. 2026 г. |
33Наблюдать | CVE-2026-52750Эксплойта нет | Ghidra < 12.1- Command Injection via URL Annotation Clicknsa · ghidra · CWE-88 | Высокая8,4 | — | 0,7 % | 10 июн. 2026 г. |
33Наблюдать | CVE-2026-52755Эксплойта нет | Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Importnsa · ghidra · CWE-22 | Высокая8,4 | — | 0,2 % | 10 июн. 2026 г. |
33Наблюдать | CVE-2026-52752Эксплойта нет | Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Namesnsa · ghidra · CWE-22 | Высокая8,4 | — | 0,2 % | 10 июн. 2026 г. |
32Наблюдать | CVE-2019-13623Proof of concept | In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive withnsa · ghidra · CWE-22 | Высокая7,8 | — | 5,0 % | 16 июл. 2019 г. |
32Наблюдать | CVE-2021-32095Эксплойта нет | U.S.nsa · emissary · CWE-862 | Высокая8,1 | — | 0,9 % | 7 мая 2021 г. |
31Наблюдать | CVE-2019-17665Эксплойта нет | NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.nsa · ghidra · CWE-427 | Высокая7,8 | — | 0,5 % | 16 окт. 2019 г. |
31Наблюдать | CVE-2019-17664Эксплойта нет | NSA Ghidra through 9.0.4 uses a potentially untrusted search path.nsa · ghidra · CWE-426 | Высокая7,8 | — | 0,4 % | 16 окт. 2019 г. |
28Наблюдать | CVE-2021-32634Эксплойта нет | Deserialization of Untrusted Data in Emissarynsa · emissary · CWE-502 | Высокая7,2 | — | 1,3 % | 21 мая 2021 г. |
28Наблюдать | CVE-2026-35581Эксплойта нет | Emissary has a Command Injection via PLACE_NAME Configuration in Executrixnsa · emissary · CWE-78 | Высокая7,2 | — | 0,9 % | 7 апр. 2026 г. |
27Наблюдать | CVE-2026-49496Эксплойта нет | Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocationnsa · ghidra · CWE-416 | Средняя6,9 | — | 0,2 % | 10 июн. 2026 г. |
26Наблюдать | CVE-2021-32093Эксплойта нет | The ConfigFileAction component of U.S.nsa · emissary · CWE-862 | Средняя6,5 | — | 1,0 % | 7 мая 2021 г. |
- CVE-2019-1694141В плане
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E
КритическаяCVSS 9,8Proof of conceptEPSS 5 %nsa · ghidra28 сент. 2019 г.
- CVE-2023-2267140В плане
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injectio
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nsa · ghidra6 янв. 2023 г.
- CVE-2021-3263939Наблюдать
Server-Side Request Forgery (SSRF) in emissary:emissary
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %nsa · emissary2 июл. 2021 г.
- CVE-2021-3264737Наблюдать
Post-authentication Remote Code Execution (RCE) in emissary:emissary
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %nsa · emissary1 июн. 2021 г.
- CVE-2019-1362537Наблюдать
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %nsa · ghidra16 июл. 2019 г.
- CVE-2026-3558036Наблюдать
Emissary has GitHub Actions Shell Injection via Workflow Inputs
КритическаяCVSS 9,1Proof of conceptEPSS 1 %nsa · emissary7 апр. 2026 г.
- CVE-2021-3209435Наблюдать
U.S.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nsa · emissary7 мая 2021 г.
- CVE-2026-3558235Наблюдать
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nsa · emissary17 апр. 2026 г.
- CVE-2026-494635Наблюдать
NSA Ghidra Auto-Analysis Annotation Command Execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nsa · ghidra29 мар. 2026 г.
- CVE-2021-3209635Наблюдать
The ConsoleAction component of U.S.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nsa · emissary7 мая 2021 г.
- CVE-2026-5275134Наблюдать
Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %nsa · ghidra10 июн. 2026 г.
- CVE-2026-5275834Наблюдать
Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %nsa · ghidra10 июн. 2026 г.
- CVE-2026-4949834Наблюдать
Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %nsa · ghidra10 июн. 2026 г.
- CVE-2026-5275434Наблюдать
Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %nsa · ghidra10 июн. 2026 г.
- CVE-2026-5275033Наблюдать
Ghidra < 12.1- Command Injection via URL Annotation Click
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %nsa · ghidra10 июн. 2026 г.
- CVE-2026-5275533Наблюдать
Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %nsa · ghidra10 июн. 2026 г.
- CVE-2026-5275233Наблюдать
Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %nsa · ghidra10 июн. 2026 г.
- CVE-2019-1362332Наблюдать
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %nsa · ghidra16 июл. 2019 г.
- CVE-2021-3209532Наблюдать
U.S.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %nsa · emissary7 мая 2021 г.
- CVE-2019-1766531Наблюдать
NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %nsa · ghidra16 окт. 2019 г.
- CVE-2019-1766431Наблюдать
NSA Ghidra through 9.0.4 uses a potentially untrusted search path.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %nsa · ghidra16 окт. 2019 г.
- CVE-2021-3263428Наблюдать
Deserialization of Untrusted Data in Emissary
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %nsa · emissary21 мая 2021 г.
- CVE-2026-3558128Наблюдать
Emissary has a Command Injection via PLACE_NAME Configuration in Executrix
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %nsa · emissary7 апр. 2026 г.
- CVE-2026-4949627Наблюдать
Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocation
СредняяCVSS 6,9Эксплойта нетEPSS 0 %nsa · ghidra10 июн. 2026 г.
- CVE-2021-3209326Наблюдать
The ConfigFileAction component of U.S.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %nsa · emissary7 мая 2021 г.