OSSEC records
12 published records for vendor ossec.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-416 Use After Free2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-674 Uncontrolled Recursion1
- CWE-787 Out-of-bounds Write1
- CWE-193 Off-by-one Error1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-8443No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-basossec · ossec · CWE-193 | Critical9.8 | — | 2.7% | Jan 29, 2020 |
40Plan | CVE-2020-8444No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durinossec · ossec · CWE-416 | Critical9.8 | — | 2.5% | Jan 29, 2020 |
40Plan | CVE-2020-8445No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlineossec · ossec · CWE-20 | Critical9.8 | — | 2.3% | Jan 29, 2020 |
40Plan | CVE-2020-8447No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durinossec · ossec · CWE-416 | Critical9.8 | — | 1.9% | Jan 29, 2020 |
36Monitor | CVE-2020-8442No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ovossec · ossec · CWE-787 | High8.8 | — | 2.4% | Jan 29, 2020 |
31Monitor | CVE-2018-19666No exploit | The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging fullossec · ossec · CWE-22 | High7.8 | — | 0.8% | Nov 29, 2018 |
30Monitor | CVE-2021-28040No exploit | An issue was discovered in OSSEC 3.6.0.ossec · ossec · CWE-674 | High7.5 | — | 1.2% | Mar 5, 2021 |
29Monitor | CVE-2014-5284Proof of concept | host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local userossec · ossec · CWE-264 | High7.2 | — | 2.4% | Dec 1, 2014 |
29Monitor | CVE-2015-3222Proof of concept | syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.ossec · ossec · CWE-264 | High7.0 | — | 2.0% | Sep 7, 2017 |
24Monitor | CVE-2016-4847No exploit | Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scripossec · web ui · CWE-79 | Medium6.1 | — | 1.3% | Apr 20, 2017 |
22Monitor | CVE-2020-8446No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with wossec · ossec · CWE-22 | Medium5.5 | — | 0.5% | Jan 29, 2020 |
22Monitor | CVE-2020-8448No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (Nossec · ossec · CWE-476 | Medium5.5 | — | 0.5% | Jan 29, 2020 |
- CVE-2020-844340Plan
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas
CriticalCVSS 9.8No exploitEPSS 3%ossec · ossecJan 29, 2020
- CVE-2020-844440Plan
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin
CriticalCVSS 9.8No exploitEPSS 2%ossec · ossecJan 29, 2020
- CVE-2020-844540Plan
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newline
CriticalCVSS 9.8No exploitEPSS 2%ossec · ossecJan 29, 2020
- CVE-2020-844740Plan
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin
CriticalCVSS 9.8No exploitEPSS 2%ossec · ossecJan 29, 2020
- CVE-2020-844236Monitor
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ov
HighCVSS 8.8No exploitEPSS 2%ossec · ossecJan 29, 2020
- CVE-2018-1966631Monitor
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full
HighCVSS 7.8No exploitEPSS 1%ossec · ossecNov 29, 2018
- CVE-2021-2804030Monitor
An issue was discovered in OSSEC 3.6.0.
HighCVSS 7.5No exploitEPSS 1%ossec · ossecMar 5, 2021
- CVE-2014-528429Monitor
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local user
HighCVSS 7.2Proof of conceptEPSS 2%ossec · ossecDec 1, 2014
- CVE-2015-322229Monitor
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
HighCVSS 7.0Proof of conceptEPSS 2%ossec · ossecSep 7, 2017
- CVE-2016-484724Monitor
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scrip
MediumCVSS 6.1No exploitEPSS 1%ossec · web uiApr 20, 2017
- CVE-2020-844622Monitor
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with w
MediumCVSS 5.5No exploitEPSS 1%ossec · ossecJan 29, 2020
- CVE-2020-844822Monitor
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (N
MediumCVSS 5.5No exploitEPSS 0%ossec · ossecJan 29, 2020