Записи centos
8 опубликованных записей вендора centos.
Профиль для исследователя
- Попали в KEV
- 1 · 12,5 %
- С эксплойтом
- 1 · 12,5 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- 2532 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-193 Off-by-one Error1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-648 Incorrect Use of Privileged APIs1
- CWE-667 Improper Locking1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2017-1000253Готовый эксплойт | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86linux · linux kernel · CWE-119 | Высокая7,8 | KEV | 10,7 % | 4 окт. 2017 г. |
32Наблюдать | CVE-2019-19906Эксплойта нет | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformecyrusimap · cyrus-sasl · CWE-193 | Высокая7,5 | — | 8,0 % | 19 дек. 2019 г. |
31Наблюдать | CVE-2020-5291Эксплойта нет | Privilege escalation in setuid mode via user namespaces in Bubblewrapprojectatomic · bubblewrap · CWE-648 | Высокая7,8 | — | 0,9 % | 31 мар. 2020 г. |
30Наблюдать | CVE-2022-24121Эксплойта нет | SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information thrunifiedoffice · total connect now · CWE-89 | Высокая7,5 | — | 1,3 % | 3 февр. 2022 г. |
27Наблюдать | CVE-2011-4144Эксплойта нет | Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local emc · documentum content server | Средняя6,8 | — | 0,3 % | 2 февр. 2012 г. |
26Наблюдать | CVE-2022-23238Эксплойта нет | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less linux · linux kernel | Средняя6,5 | — | 0,7 % | 10 авг. 2022 г. |
24Наблюдать | CVE-2021-20315Эксплойта нет | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" orgnome · gnome-shell · CWE-667 | Средняя6,1 | — | 0,2 % | 18 февр. 2022 г. |
19Наблюдать | CVE-2007-6283Эксплойта нет | Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perfofedoraproject · fedora core · CWE-200 | Средняя4,9 | — | 0,4 % | 17 дек. 2007 г. |
- CVE-2017-100025364На этой неделе
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 11 %linux · linux kernel4 окт. 2017 г.
- CVE-2019-1990632Наблюдать
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malforme
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %cyrusimap · cyrus-sasl19 дек. 2019 г.
- CVE-2020-529131Наблюдать
Privilege escalation in setuid mode via user namespaces in Bubblewrap
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %projectatomic · bubblewrap31 мар. 2020 г.
- CVE-2022-2412130Наблюдать
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information thr
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %unifiedoffice · total connect now3 февр. 2022 г.
- CVE-2011-414427Наблюдать
Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local
СредняяCVSS 6,8Эксплойта нетEPSS 0 %emc · documentum content server2 февр. 2012 г.
- CVE-2022-2323826Наблюдать
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less
СредняяCVSS 6,5Эксплойта нетEPSS 1 %linux · linux kernel10 авг. 2022 г.
- CVE-2021-2031524Наблюдать
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or
СредняяCVSS 6,1Эксплойта нетEPSS 0 %gnome · gnome-shell18 февр. 2022 г.
- CVE-2007-628319Наблюдать
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perfo
СредняяCVSS 4,9Эксплойта нетEPSS 0 %fedoraproject · fedora core17 дек. 2007 г.