Skip to content
Noroxi

OSSEC records

12 published records for vendor ossec.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas

    CriticalCVSS 9.8No exploitEPSS 3%

    ossec · ossecJan 29, 2020

  • In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin

    CriticalCVSS 9.8No exploitEPSS 2%

    ossec · ossecJan 29, 2020

  • In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newline

    CriticalCVSS 9.8No exploitEPSS 2%

    ossec · ossecJan 29, 2020

  • In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin

    CriticalCVSS 9.8No exploitEPSS 2%

    ossec · ossecJan 29, 2020

  • CVE-2020-8442
    36Monitor

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ov

    HighCVSS 8.8No exploitEPSS 2%

    ossec · ossecJan 29, 2020

  • The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full

    HighCVSS 7.8No exploitEPSS 1%

    ossec · ossecNov 29, 2018

  • An issue was discovered in OSSEC 3.6.0.

    HighCVSS 7.5No exploitEPSS 1%

    ossec · ossecMar 5, 2021

  • CVE-2014-5284
    29Monitor

    host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local user

    HighCVSS 7.2Proof of conceptEPSS 2%

    ossec · ossecDec 1, 2014

  • CVE-2015-3222
    29Monitor

    syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

    HighCVSS 7.0Proof of conceptEPSS 2%

    ossec · ossecSep 7, 2017

  • CVE-2016-4847
    24Monitor

    Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scrip

    MediumCVSS 6.1No exploitEPSS 1%

    ossec · web uiApr 20, 2017

  • CVE-2020-8446
    22Monitor

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with w

    MediumCVSS 5.5No exploitEPSS 1%

    ossec · ossecJan 29, 2020

  • CVE-2020-8448
    22Monitor

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (N

    MediumCVSS 5.5No exploitEPSS 0%

    ossec · ossecJan 29, 2020