Перейти к содержимому
Noroxi

Записи Debian

10 221 опубликованных записей вендора debian.

Профиль для исследователя

Попали в KEV
123 · 1,2 %
С эксплойтом
201 · 2 %
Pre-auth RCE
752
С записью об исправлении
97,4 %
Медиана: публикация → KEV
362 дн.

Все записи

10 000+ записей
  • CVE-2021-44228
    100Срочно

    Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j10 дек. 2021 г.

  • CVE-2022-0543
    100Срочно

    It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %

    redis · redis18 февр. 2022 г.

  • CVE-2025-32433
    100Срочно

    Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %

    erlang · erlang\/otp16 апр. 2025 г.

  • CVE-2014-6271
    99Срочно

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    gnu · bash24 сент. 2014 г.

  • CVE-2012-1823
    99Срочно

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php11 мая 2012 г.

  • CVE-2018-7600
    99Срочно

    Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    drupal · drupal29 мар. 2018 г.

  • CVE-2019-10149
    99Срочно

    A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    exim · exim5 июн. 2019 г.

  • CVE-2014-7169
    99Срочно

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    gnu · bash24 сент. 2014 г.

  • CVE-2025-24813
    99Срочно

    Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · tomcat10 мар. 2025 г.

  • CVE-2023-46604
    99Срочно

    Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · activemq27 окт. 2023 г.

  • CVE-2019-11043
    99Срочно

    Underflow in PHP-FPM can lead to RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php28 окт. 2019 г.

  • CVE-2020-16846
    99Срочно

    An issue was discovered in SaltStack Salt through 3002.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    saltstack · salt6 нояб. 2020 г.

  • CVE-2017-7494
    99Срочно

    Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    samba · samba30 мая 2017 г.

  • CVE-2020-1938
    99Срочно

    When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · geode24 февр. 2020 г.

  • CVE-2018-7602
    99Срочно

    Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    drupal · drupal19 июл. 2018 г.

  • CVE-2026-24061
    99Срочно

    telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    gnu · inetutils21 янв. 2026 г.

  • CVE-2020-7247
    99Срочно

    smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    openbsd · opensmtpd29 янв. 2020 г.

  • CVE-2012-0507
    98Срочно

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    oracle · jre7 июн. 2012 г.

  • CVE-2020-11651
    98Срочно

    An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    saltstack · salt30 апр. 2020 г.

  • CVE-2009-1151
    98Срочно

    Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    phpmyadmin · phpmyadmin26 мар. 2009 г.

  • CVE-2016-3427
    97Срочно

    Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    oracle · jdk21 апр. 2016 г.

  • CVE-2021-40438
    96Срочно

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    resf · rocky linux16 сент. 2021 г.

  • CVE-2021-45046
    96Срочно

    Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j14 дек. 2021 г.

  • CVE-2016-8735
    96Срочно

    Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %

    apache · tomcat6 апр. 2017 г.

  • CVE-2023-4863
    95Срочно

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %

    google · chrome12 сент. 2023 г.