Skip to content
Noroxi

starwindsoftware records

30 published records for vendor starwindsoftware.

Researcher profile

Entered KEV
1 · 3.3%
Weaponized
1 · 3.3%
Pre-auth RCE
2
With a fix record
80%
Median publish → KEV
150 days

All records

30 records
  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    HighCVSS 7.8KEVWeaponizedEPSS 94%

    polkit project · polkitJan 28, 2022

  • NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-

    CriticalCVSS 9.8No exploitEPSS 18%

    mozilla · nssDec 8, 2021

  • A flaw was found in the REST API in StarWind Stack.

    CriticalCVSS 9.8No exploitEPSS 1%

    starwindsoftware · nasFeb 6, 2022

  • A flaw was found in StarWind iSCSI target.

    CriticalCVSS 9.8No exploitEPSS 1%

    starwindsoftware · iscsi sanFeb 6, 2022

  • An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.

    HighCVSS 8.3Proof of conceptEPSS 13%

    unicode · unicodeNov 1, 2021

  • CVE-2018-3839
    36Monitor

    An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.

    HighCVSS 8.8No exploitEPSS 3%

    libsdl · sdl imageApr 10, 2018

  • StarWind SAN and NAS v0.2 build 1914 allow remote code execution.

    HighCVSS 8.8No exploitEPSS 2%

    starwindsoftware · starwind san \& nasJun 3, 2022

  • A flaw was found in the REST API.

    HighCVSS 8.8No exploitEPSS 1%

    starwindsoftware · command centerJan 23, 2022

  • A flaw was found in StarWind Stack.

    HighCVSS 8.8No exploitEPSS 1%

    starwindsoftware · nasFeb 6, 2022

  • An issue was discovered in the Linux kernel before 5.10.

    HighCVSS 7.8No exploitEPSS 1%

    linux · linux kernelJun 7, 2021

  • SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SD

    HighCVSS 7.8No exploitEPSS 1%

    libsdl · simple directmedia layerJan 19, 2021

  • A flaw was found in StarWind iSCSI target.

    HighCVSS 7.5No exploitEPSS 1%

    starwindsoftware · iscsi sanFeb 6, 2022

  • A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.

    HighCVSS 7.2No exploitEPSS 3%

    linux · linux kernelOct 6, 2020

  • sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplement

    HighCVSS 7.0Proof of conceptEPSS 3%

    openbsd · opensshSep 26, 2021

  • A flaw was found in RPM's signature check functionality when reading a package file.

    HighCVSS 7.0No exploitEPSS 1%

    rpm · rpmMar 26, 2021

  • In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesys

    HighCVSS 7.1No exploitEPSS 0%

    linux · linux kernelAug 19, 2020

  • In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Qua

    MediumCVSS 6.5No exploitEPSS 3%

    cabextract project · cabextractOct 22, 2018

  • The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/

    MediumCVSS 6.5No exploitEPSS 2%

    mit · kerberos 5Aug 23, 2021

  • The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers

    MediumCVSS 6.7No exploitEPSS 0%

    linux · linux kernelOct 20, 2021

  • Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the

    MediumCVSS 5.9No exploitEPSS 1%

    tinc-vpn · tincOct 10, 2018

  • CVE-2018-3837
    22Monitor

    An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2

    MediumCVSS 5.5No exploitEPSS 1%

    libsdl · sdl imageApr 10, 2018

  • CVE-2020-0427
    22Monitor

    In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.

    MediumCVSS 5.5No exploitEPSS 0%

    google · androidSep 17, 2020

  • An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelApr 14, 2021

  • A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direc

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelSep 15, 2020

  • A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelDec 1, 2020