centos records
8 published records for vendor centos.
Researcher profile
- Entered KEV
- 1 · 12.5%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- 2532 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-193 Off-by-one Error1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-648 Incorrect Use of Privileged APIs1
- CWE-667 Improper Locking1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2017-1000253Weaponized | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86linux · linux kernel · CWE-119 | High7.8 | KEV | 10.7% | Oct 4, 2017 |
32Monitor | CVE-2019-19906No exploit | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformecyrusimap · cyrus-sasl · CWE-193 | High7.5 | — | 8.0% | Dec 19, 2019 |
31Monitor | CVE-2020-5291No exploit | Privilege escalation in setuid mode via user namespaces in Bubblewrapprojectatomic · bubblewrap · CWE-648 | High7.8 | — | 0.9% | Mar 31, 2020 |
30Monitor | CVE-2022-24121No exploit | SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information thrunifiedoffice · total connect now · CWE-89 | High7.5 | — | 1.3% | Feb 3, 2022 |
27Monitor | CVE-2011-4144No exploit | Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local emc · documentum content server | Medium6.8 | — | 0.3% | Feb 2, 2012 |
26Monitor | CVE-2022-23238No exploit | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less linux · linux kernel | Medium6.5 | — | 0.7% | Aug 10, 2022 |
24Monitor | CVE-2021-20315No exploit | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" orgnome · gnome-shell · CWE-667 | Medium6.1 | — | 0.2% | Feb 18, 2022 |
19Monitor | CVE-2007-6283No exploit | Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perfofedoraproject · fedora core · CWE-200 | Medium4.9 | — | 0.4% | Dec 17, 2007 |
- CVE-2017-100025364This week
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86
HighCVSS 7.8KEVWeaponizedEPSS 11%linux · linux kernelOct 4, 2017
- CVE-2019-1990632Monitor
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malforme
HighCVSS 7.5No exploitEPSS 8%cyrusimap · cyrus-saslDec 19, 2019
- CVE-2020-529131Monitor
Privilege escalation in setuid mode via user namespaces in Bubblewrap
HighCVSS 7.8No exploitEPSS 1%projectatomic · bubblewrapMar 31, 2020
- CVE-2022-2412130Monitor
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information thr
HighCVSS 7.5No exploitEPSS 1%unifiedoffice · total connect nowFeb 3, 2022
- CVE-2011-414427Monitor
Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local
MediumCVSS 6.8No exploitEPSS 0%emc · documentum content serverFeb 2, 2012
- CVE-2022-2323826Monitor
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less
MediumCVSS 6.5No exploitEPSS 1%linux · linux kernelAug 10, 2022
- CVE-2021-2031524Monitor
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or
MediumCVSS 6.1No exploitEPSS 0%gnome · gnome-shellFeb 18, 2022
- CVE-2007-628319Monitor
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perfo
MediumCVSS 4.9No exploitEPSS 0%fedoraproject · fedora coreDec 17, 2007