starwindsoftware records
30 published records for vendor starwindsoftware.
Researcher profile
- Entered KEV
- 1 · 3.3%
- Weaponized
- 1 · 3.3%
- Pre-auth RCE
- 2
- With a fix record
- 80%
- Median publish → KEV
- 150 days
Recurring classes
- CWE-787 Out-of-bounds Write5
- CWE-287 Improper Authentication3
- CWE-125 Out-of-bounds Read3
- CWE-416 Use After Free2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-400 Uncontrolled Resource Consumption2
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2021-4034Weaponized | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | High7.8 | KEV | 94.3% | Jan 28, 2022 |
44Plan | CVE-2021-43527No exploit | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-mozilla · nss · CWE-787 | Critical9.8 | — | 17.6% | Dec 8, 2021 |
39Monitor | CVE-2022-24552No exploit | A flaw was found in the REST API in StarWind Stack.starwindsoftware · nas · CWE-78 | Critical9.8 | — | 1.3% | Feb 6, 2022 |
39Monitor | CVE-2013-20004No exploit | A flaw was found in StarWind iSCSI target.starwindsoftware · iscsi san · CWE-400 | Critical9.8 | — | 1.2% | Feb 6, 2022 |
37Monitor | CVE-2021-42574Proof of concept | An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.unicode · unicode · CWE-94 | High8.3 | — | 12.9% | Nov 1, 2021 |
36Monitor | CVE-2018-3839No exploit | An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.libsdl · sdl image · CWE-787 | High8.8 | — | 2.6% | Apr 10, 2018 |
36Monitor | CVE-2022-32268No exploit | StarWind SAN and NAS v0.2 build 1914 allow remote code execution.starwindsoftware · starwind san \& nas | High8.8 | — | 2.3% | Jun 3, 2022 |
35Monitor | CVE-2022-23858No exploit | A flaw was found in the REST API.starwindsoftware · command center | High8.8 | — | 1.1% | Jan 23, 2022 |
35Monitor | CVE-2022-24551No exploit | A flaw was found in StarWind Stack.starwindsoftware · nas · CWE-287 | High8.8 | — | 0.9% | Feb 6, 2022 |
31Monitor | CVE-2020-36385No exploit | An issue was discovered in the Linux kernel before 5.10.linux · linux kernel · CWE-416 | High7.8 | — | 1.5% | Jun 7, 2021 |
31Monitor | CVE-2020-14409No exploit | SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDlibsdl · simple directmedia layer · CWE-190 | High7.8 | — | 1.3% | Jan 19, 2021 |
30Monitor | CVE-2007-20001No exploit | A flaw was found in StarWind iSCSI target.starwindsoftware · iscsi san · CWE-400 | High7.5 | — | 1.1% | Feb 6, 2022 |
29Monitor | CVE-2020-25643No exploit | A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.linux · linux kernel · CWE-20 | High7.2 | — | 3.3% | Oct 6, 2020 |
29Monitor | CVE-2021-41617Proof of concept | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplementopenbsd · openssh | High7.0 | — | 2.5% | Sep 26, 2021 |
28Monitor | CVE-2021-20271No exploit | A flaw was found in RPM's signature check functionality when reading a package file.rpm · rpm · CWE-345 | High7.0 | — | 0.8% | Mar 26, 2021 |
28Monitor | CVE-2020-24394No exploit | In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesyslinux · linux kernel · CWE-732 | High7.1 | — | 0.4% | Aug 19, 2020 |
27Monitor | CVE-2018-18584No exploit | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quacabextract project · cabextract · CWE-787 | Medium6.5 | — | 3.1% | Oct 22, 2018 |
27Monitor | CVE-2021-37750No exploit | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/mit · kerberos 5 · CWE-476 | Medium6.5 | — | 2.2% | Aug 23, 2021 |
26Monitor | CVE-2021-42739No exploit | The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and driverslinux · linux kernel · CWE-787 | Medium6.7 | — | 0.5% | Oct 20, 2021 |
23Monitor | CVE-2018-16758No exploit | Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the tinc-vpn · tinc · CWE-306 | Medium5.9 | — | 0.9% | Oct 10, 2018 |
22Monitor | CVE-2018-3837No exploit | An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2libsdl · sdl image · CWE-125 | Medium5.5 | — | 1.2% | Apr 10, 2018 |
22Monitor | CVE-2020-0427No exploit | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.google · android · CWE-125 | Medium5.5 | — | 0.5% | Sep 17, 2020 |
22Monitor | CVE-2020-36322No exploit | An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.linux · linux kernel · CWE-459 | Medium5.5 | — | 0.4% | Apr 14, 2021 |
22Monitor | CVE-2020-14314No exploit | A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direclinux · linux kernel · CWE-125 | Medium5.5 | — | 0.4% | Sep 15, 2020 |
22Monitor | CVE-2020-25704No exploit | A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.linux · linux kernel · CWE-401 | Medium5.5 | — | 0.4% | Dec 1, 2020 |
- CVE-2021-403489Now
A local privilege escalation vulnerability was found on polkit's pkexec utility.
HighCVSS 7.8KEVWeaponizedEPSS 94%polkit project · polkitJan 28, 2022
- CVE-2021-4352744Plan
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-
CriticalCVSS 9.8No exploitEPSS 18%mozilla · nssDec 8, 2021
- CVE-2022-2455239Monitor
A flaw was found in the REST API in StarWind Stack.
CriticalCVSS 9.8No exploitEPSS 1%starwindsoftware · nasFeb 6, 2022
- CVE-2013-2000439Monitor
A flaw was found in StarWind iSCSI target.
CriticalCVSS 9.8No exploitEPSS 1%starwindsoftware · iscsi sanFeb 6, 2022
- CVE-2021-4257437Monitor
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.
HighCVSS 8.3Proof of conceptEPSS 13%unicode · unicodeNov 1, 2021
- CVE-2018-383936Monitor
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.
HighCVSS 8.8No exploitEPSS 3%libsdl · sdl imageApr 10, 2018
- CVE-2022-3226836Monitor
StarWind SAN and NAS v0.2 build 1914 allow remote code execution.
HighCVSS 8.8No exploitEPSS 2%starwindsoftware · starwind san \& nasJun 3, 2022
- CVE-2022-2385835Monitor
A flaw was found in the REST API.
HighCVSS 8.8No exploitEPSS 1%starwindsoftware · command centerJan 23, 2022
- CVE-2022-2455135Monitor
A flaw was found in StarWind Stack.
HighCVSS 8.8No exploitEPSS 1%starwindsoftware · nasFeb 6, 2022
- CVE-2020-3638531Monitor
An issue was discovered in the Linux kernel before 5.10.
HighCVSS 7.8No exploitEPSS 1%linux · linux kernelJun 7, 2021
- CVE-2020-1440931Monitor
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SD
HighCVSS 7.8No exploitEPSS 1%libsdl · simple directmedia layerJan 19, 2021
- CVE-2007-2000130Monitor
A flaw was found in StarWind iSCSI target.
HighCVSS 7.5No exploitEPSS 1%starwindsoftware · iscsi sanFeb 6, 2022
- CVE-2020-2564329Monitor
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.
HighCVSS 7.2No exploitEPSS 3%linux · linux kernelOct 6, 2020
- CVE-2021-4161729Monitor
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplement
HighCVSS 7.0Proof of conceptEPSS 3%openbsd · opensshSep 26, 2021
- CVE-2021-2027128Monitor
A flaw was found in RPM's signature check functionality when reading a package file.
HighCVSS 7.0No exploitEPSS 1%rpm · rpmMar 26, 2021
- CVE-2020-2439428Monitor
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesys
HighCVSS 7.1No exploitEPSS 0%linux · linux kernelAug 19, 2020
- CVE-2018-1858427Monitor
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Qua
MediumCVSS 6.5No exploitEPSS 3%cabextract project · cabextractOct 22, 2018
- CVE-2021-3775027Monitor
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/
MediumCVSS 6.5No exploitEPSS 2%mit · kerberos 5Aug 23, 2021
- CVE-2021-4273926Monitor
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers
MediumCVSS 6.7No exploitEPSS 0%linux · linux kernelOct 20, 2021
- CVE-2018-1675823Monitor
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the
MediumCVSS 5.9No exploitEPSS 1%tinc-vpn · tincOct 10, 2018
- CVE-2018-383722Monitor
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
MediumCVSS 5.5No exploitEPSS 1%libsdl · sdl imageApr 10, 2018
- CVE-2020-042722Monitor
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.
MediumCVSS 5.5No exploitEPSS 0%google · androidSep 17, 2020
- CVE-2020-3632222Monitor
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelApr 14, 2021
- CVE-2020-1431422Monitor
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direc
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelSep 15, 2020
- CVE-2020-2570422Monitor
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelDec 1, 2020