Записи canonical
4 318 опубликованных записей вендора canonical.
Профиль для исследователя
- Попали в KEV
- 47 · 1,1 %
- С эксплойтом
- 100 · 2,3 %
- Pre-auth RCE
- 493
- С записью об исправлении
- 88,7 %
- Медиана: публикация → KEV
- 1939 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer375
- CWE-125 Out-of-bounds Read295
- CWE-787 Out-of-bounds Write235
- CWE-20 Improper Input Validation219
- CWE-416 Use After Free212
- CWE-476 NULL Pointer Dereference190
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 318 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2022-0543Готовый эксплойт | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Критическая10,0 | KEV | 99,4 % | 18 февр. 2022 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2019-10149Готовый эксплойт | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Критическая9,8 | KEV | 100,0 % | 5 июн. 2019 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2019-11043Готовый эксплойт | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Критическая9,8 | KEV | 99,8 % | 28 окт. 2019 г. |
99Срочно | CVE-2020-7247Готовый эксплойт | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Критическая9,8 | KEV | 99,0 % | 29 янв. 2020 г. |
98Срочно | CVE-2013-0422Готовый эксплойт | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Критическая9,8 | KEV | 97,0 % | 10 янв. 2013 г. |
98Срочно | CVE-2011-3544Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Критическая9,8 | KEV | 96,7 % | 19 окт. 2011 г. |
98Срочно | CVE-2020-11651Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Критическая9,8 | KEV | 96,6 % | 30 апр. 2020 г. |
98Срочно | CVE-2010-0840Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and oracle · jre | Критическая9,8 | KEV | 96,3 % | 1 апр. 2010 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
96Срочно | CVE-2016-8735Готовый эксплойт | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Критическая9,8 | KEV | 90,3 % | 6 апр. 2017 г. |
94Срочно | CVE-2018-6789Готовый эксплойт | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Критическая9,8 | KEV | 82,1 % | 8 февр. 2018 г. |
92Срочно | CVE-2017-12617Готовый эксплойт | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 100,0 % | 3 окт. 2017 г. |
92Срочно | CVE-2016-3714Готовый эксплойт | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | Высокая8,4 | KEV | 97,5 % | 5 мая 2016 г. |
91Срочно | CVE-2010-4344Готовый эксплойт | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Критическая9,8 | KEV | 71,7 % | 14 дек. 2010 г. |
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
89Срочно | CVE-2021-4034Готовый эксплойт | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Высокая7,8 | KEV | 94,3 % | 28 янв. 2022 г. |
86Срочно | CVE-2013-1690Готовый эксплойт | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Высокая8,8 | KEV | 69,0 % | 25 июн. 2013 г. |
86Срочно | CVE-2015-4495Готовый эксплойт | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | Высокая8,8 | KEV | 68,6 % | 7 авг. 2015 г. |
85Срочно | CVE-2023-4911Готовый эксплойт | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | Высокая7,8 | KEV | 81,4 % | 3 окт. 2023 г. |
83Срочно | CVE-2016-5195Готовый эксплойт | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | Высокая7,0 | KEV | 83,5 % | 10 нояб. 2016 г. |
83Срочно | CVE-2019-2215Готовый эксплойт | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.google · android · CWE-416 | Высокая7,8 | KEV | 72,1 % | 11 окт. 2019 г. |
82Срочно | CVE-2020-1472Готовый эксплойт | Netlogon Elevation of Privilege Vulnerabilitymicrosoft · windows server 1903 | Средняя5,5 | KEV | 99,4 % | 17 авг. 2020 г. |
82Срочно | CVE-2020-11652Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt · CWE-22 | Средняя6,5 | KEV | 86,2 % | 30 апр. 2020 г. |
- CVE-2022-0543100Срочно
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %redis · redis18 февр. 2022 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2019-1014999Срочно
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %exim · exim5 июн. 2019 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2019-1104399Срочно
Underflow in PHP-FPM can lead to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php28 окт. 2019 г.
- CVE-2020-724799Срочно
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %openbsd · opensmtpd29 янв. 2020 г.
- CVE-2013-042298Срочно
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk10 янв. 2013 г.
- CVE-2011-354498Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk19 окт. 2011 г.
- CVE-2020-1165198Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %saltstack · salt30 апр. 2020 г.
- CVE-2010-084098Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %oracle · jre1 апр. 2010 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2016-873596Срочно
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %apache · tomcat6 апр. 2017 г.
- CVE-2018-678994Срочно
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 82 %exim · exim8 февр. 2018 г.
- CVE-2017-1261792Срочно
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat3 окт. 2017 г.
- CVE-2016-371492Срочно
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 97 %imagemagick · imagemagick5 мая 2016 г.
- CVE-2010-434491Срочно
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %exim · exim14 дек. 2010 г.
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2021-403489Срочно
A local privilege escalation vulnerability was found on polkit's pkexec utility.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 94 %polkit project · polkit28 янв. 2022 г.
- CVE-2013-169086Срочно
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox25 июн. 2013 г.
- CVE-2015-449586Срочно
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox7 авг. 2015 г.
- CVE-2023-491185Срочно
Glibc: buffer overflow in ld.so leading to privilege escalation
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 81 %gnu · glibc3 окт. 2023 г.
- CVE-2016-519583Срочно
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 84 %linux · linux kernel10 нояб. 2016 г.
- CVE-2019-221583Срочно
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 72 %google · android11 окт. 2019 г.
- CVE-2020-147282Срочно
Netlogon Elevation of Privilege Vulnerability
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 99 %microsoft · windows server 190317 авг. 2020 г.
- CVE-2020-1165282Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 86 %saltstack · salt30 апр. 2020 г.