Записи windriver
48 опубликованных записей вендора windriver.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,1 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 6,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation7
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-190 Integer Overflow or Wraparound4
- CWE-787 Out-of-bounds Write3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-125 Out-of-bounds Read2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
48 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2019-12255Proof of concept | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).windriver · vxworks · CWE-120 | Критическая9,8 | — | 75,3 % | 9 авг. 2019 г. |
62На этой неделе | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Критическая10,0 | — | 72,6 % | 7 мар. 2003 г. |
60На этой неделе | CVE-2019-12257Эксплойта нет | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component.windriver · vxworks · CWE-120 | Высокая8,8 | — | 84,2 % | 9 авг. 2019 г. |
53В плане | CVE-2010-2965Эксплойта нет | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Критическая9,8 | — | 47,4 % | 5 авг. 2010 г. |
47В плане | CVE-2019-12256Эксплойта нет | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component.windriver · vxworks · CWE-120 | Критическая9,8 | — | 26,6 % | 9 авг. 2019 г. |
46В плане | CVE-2019-12260Эксплойта нет | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4).windriver · vxworks · CWE-120 | Критическая9,8 | — | 22,8 % | 9 авг. 2019 г. |
42В плане | CVE-2019-12261Эксплойта нет | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4).windriver · vxworks · CWE-120 | Критическая9,8 | — | 9,0 % | 9 авг. 2019 г. |
42В плане | CVE-2013-0714Эксплойта нет | IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of servwindriver · vxworks · CWE-20 | Критическая10,0 | — | 6,4 % | 20 мар. 2013 г. |
41В плане | CVE-2007-2736Proof of concept | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in thehp · hp-ux | Критическая10,0 | — | 4,1 % | 17 мая 2007 г. |
40В плане | CVE-2019-12262Эксплойта нет | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component.windriver · vxworks | Критическая9,8 | — | 4,1 % | 14 авг. 2019 г. |
40В плане | CVE-2020-35198Эксплойта нет | An issue was discovered in Wind River VxWorks 7.windriver · vxworks · CWE-190 | Критическая9,8 | — | 2,5 % | 12 мая 2021 г. |
40В плане | CVE-2021-29998Эксплойта нет | An issue was discovered in Wind River VxWorks before 6.5.windriver · vxworks · CWE-787 | Критическая9,8 | — | 2,4 % | 13 апр. 2021 г. |
40В плане | CVE-2016-20009Эксплойта нет | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7.windriver · vxworks · CWE-787 | Критическая9,8 | — | 1,9 % | 11 мар. 2021 г. |
40В плане | CVE-2021-29999Эксплойта нет | An issue was discovered in Wind River VxWorks through 6.8.windriver · vxworks · CWE-787 | Критическая9,8 | — | 1,8 % | 13 апр. 2021 г. |
39Наблюдать | CVE-2019-12265Эксплойта нет | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.windriver · vxworks · CWE-401 | Средняя5,3 | — | 59,8 % | 9 авг. 2019 г. |
39Наблюдать | CVE-2008-2476Эксплойта нет | The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 Fforce10 · ftos · CWE-20 | Критическая9,3 | — | 7,4 % | 3 окт. 2008 г. |
39Наблюдать | CVE-2020-10288Эксплойта нет | RVD#3327: No authentication required for accesing ABB IRC5 FTP serverabb · robotware · CWE-284 | Критическая9,8 | — | 1,4 % | 15 июл. 2020 г. |
37Наблюдать | CVE-2019-12258Готовый эксплойт | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component.windriver · vxworks · CWE-384 | Высокая7,5 | — | 22,8 % | 9 авг. 2019 г. |
35Наблюдать | CVE-2021-3450Proof of concept | CA certificate check bypass with X509_V_FLAG_X509_STRICTopenssl · openssl · CWE-295 | Высокая7,4 | — | 18,3 % | 25 мар. 2021 г. |
35Наблюдать | CVE-2007-4938Proof of concept | Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (appibm · aix · CWE-119 | Высокая7,6 | — | 16,0 % | 18 сент. 2007 г. |
35Наблюдать | CVE-2019-12259Эксплойта нет | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component.windriver · vxworks · CWE-476 | Высокая7,5 | — | 15,9 % | 9 авг. 2019 г. |
35Наблюдать | CVE-2023-38346Эксплойта нет | An issue was discovered in Wind River VxWorks 6.9 and 7.windriver · vxworks · CWE-22 | Высокая8,8 | — | 1,5 % | 22 сент. 2023 г. |
34Наблюдать | CVE-2015-7599Эксплойта нет | Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC)windriver · vxworks · CWE-190 | Высокая8,1 | — | 5,9 % | 7 февр. 2017 г. |
33Наблюдать | CVE-2007-1043Proof of concept | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and hp · hp-ux | Высокая7,5 | — | 8,3 % | 21 февр. 2007 г. |
33Наблюдать | CVE-2019-12263Эксплойта нет | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4).windriver · vxworks · CWE-362 | Высокая8,1 | — | 3,2 % | 9 авг. 2019 г. |
- CVE-2019-1225562На этой неделе
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).
КритическаяCVSS 9,8Proof of conceptEPSS 75 %windriver · vxworks9 авг. 2019 г.
- CVE-2002-133762На этой неделе
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
КритическаяCVSS 10,0Proof of conceptEPSS 73 %sendmail · sendmail7 мар. 2003 г.
- CVE-2019-1225760На этой неделе
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component.
ВысокаяCVSS 8,8Эксплойта нетEPSS 84 %windriver · vxworks9 авг. 2019 г.
- CVE-2010-296553В плане
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
КритическаяCVSS 9,8Эксплойта нетEPSS 47 %rockwellautomation · 1756-enbt\/a firmware5 авг. 2010 г.
- CVE-2019-1225647В плане
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component.
КритическаяCVSS 9,8Эксплойта нетEPSS 27 %windriver · vxworks9 авг. 2019 г.
- CVE-2019-1226046В плане
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4).
КритическаяCVSS 9,8Эксплойта нетEPSS 23 %windriver · vxworks9 авг. 2019 г.
- CVE-2019-1226142В плане
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4).
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %windriver · vxworks9 авг. 2019 г.
- CVE-2013-071442В плане
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %windriver · vxworks20 мар. 2013 г.
- CVE-2007-273641В плане
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the
КритическаяCVSS 10,0Proof of conceptEPSS 4 %hp · hp-ux17 мая 2007 г.
- CVE-2019-1226240В плане
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %windriver · vxworks14 авг. 2019 г.
- CVE-2020-3519840В плане
An issue was discovered in Wind River VxWorks 7.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %windriver · vxworks12 мая 2021 г.
- CVE-2021-2999840В плане
An issue was discovered in Wind River VxWorks before 6.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %windriver · vxworks13 апр. 2021 г.
- CVE-2016-2000940В плане
A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %windriver · vxworks11 мар. 2021 г.
- CVE-2021-2999940В плане
An issue was discovered in Wind River VxWorks through 6.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %windriver · vxworks13 апр. 2021 г.
- CVE-2019-1226539Наблюдать
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.
СредняяCVSS 5,3Эксплойта нетEPSS 60 %windriver · vxworks9 авг. 2019 г.
- CVE-2008-247639Наблюдать
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 F
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %force10 · ftos3 окт. 2008 г.
- CVE-2020-1028839Наблюдать
RVD#3327: No authentication required for accesing ABB IRC5 FTP server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · robotware15 июл. 2020 г.
- CVE-2019-1225837Наблюдать
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 23 %windriver · vxworks9 авг. 2019 г.
- CVE-2021-345035Наблюдать
CA certificate check bypass with X509_V_FLAG_X509_STRICT
ВысокаяCVSS 7,4Proof of conceptEPSS 18 %openssl · openssl25 мар. 2021 г.
- CVE-2007-493835Наблюдать
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (app
ВысокаяCVSS 7,6Proof of conceptEPSS 16 %ibm · aix18 сент. 2007 г.
- CVE-2019-1225935Наблюдать
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component.
ВысокаяCVSS 7,5Эксплойта нетEPSS 16 %windriver · vxworks9 авг. 2019 г.
- CVE-2023-3834635Наблюдать
An issue was discovered in Wind River VxWorks 6.9 and 7.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %windriver · vxworks22 сент. 2023 г.
- CVE-2015-759934Наблюдать
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC)
ВысокаяCVSS 8,1Эксплойта нетEPSS 6 %windriver · vxworks7 февр. 2017 г.
- CVE-2007-104333Наблюдать
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %hp · hp-ux21 февр. 2007 г.
- CVE-2019-1226333Наблюдать
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4).
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %windriver · vxworks9 авг. 2019 г.