Записи fedoraproject
5 456 опубликованных записей вендора fedoraproject.
Профиль для исследователя
- Попали в KEV
- 88 · 1,6 %
- С эксплойтом
- 117 · 2,1 %
- Pre-auth RCE
- 332
- С записью об исправлении
- 92,7 %
- Медиана: публикация → KEV
- 170 дн.
Повторяющиеся классы
- CWE-416 Use After Free522
- CWE-787 Out-of-bounds Write376
- CWE-125 Out-of-bounds Read309
- CWE-20 Improper Input Validation225
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer193
- CWE-476 NULL Pointer Dereference187
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 456 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
100Срочно | CVE-2015-3306Готовый эксплойт | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.proftpd · proftpd · CWE-284 | Критическая10,0 | KEV | 99,5 % | 18 мая 2015 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2021-41773Готовый эксплойт | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 5 окт. 2021 г. |
99Срочно | CVE-2024-4577Готовый эксплойт | Argument Injection in PHP-CGIphp · php · CWE-78 | Критическая9,8 | KEV | 100,0 % | 9 июн. 2024 г. |
99Срочно | CVE-2021-42013Готовый эксплойт | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 7 окт. 2021 г. |
99Срочно | CVE-2019-11043Готовый эксплойт | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Критическая9,8 | KEV | 99,8 % | 28 окт. 2019 г. |
99Срочно | CVE-2020-16846Готовый эксплойт | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Критическая9,8 | KEV | 99,6 % | 6 нояб. 2020 г. |
99Срочно | CVE-2020-1938Готовый эксплойт | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Критическая9,8 | KEV | 99,3 % | 24 февр. 2020 г. |
99Срочно | CVE-2020-7247Готовый эксплойт | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Критическая9,8 | KEV | 99,0 % | 29 янв. 2020 г. |
98Срочно | CVE-2019-5544Готовый эксплойт | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Критическая9,8 | KEV | 97,3 % | 6 дек. 2019 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
95Срочно | CVE-2023-4863Готовый эксплойт | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Высокая8,8 | KEV | 100,0 % | 12 сент. 2023 г. |
93Срочно | CVE-2021-39144Готовый эксплойт | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Высокая8,5 | KEV | 98,1 % | 23 авг. 2021 г. |
91Срочно | CVE-2021-22204Готовый эксплойт | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing texiftool project · exiftool · CWE-94 | Высокая7,8 | KEV | 100,0 % | 23 апр. 2021 г. |
91Срочно | CVE-2021-3156Готовый эксплойт | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Высокая7,8 | KEV | 100,0 % | 26 янв. 2021 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
90Срочно | CVE-2015-5477Готовый эксплойт | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | Высокая7,5 | KEV | 99,4 % | 29 июл. 2015 г. |
90Срочно | CVE-2019-5418Готовый эксплойт | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted acceprubyonrails · rails · CWE-22 | Высокая7,5 | KEV | 98,5 % | 27 мар. 2019 г. |
90Срочно | CVE-2021-21224Готовый эксплойт | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craftgoogle · chrome · CWE-843 | Высокая8,8 | KEV | 84,2 % | 26 апр. 2021 г. |
90Срочно | CVE-2021-44026Готовый эксплойт | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Критическая9,8 | KEV | 69,9 % | 19 нояб. 2021 г. |
89Срочно | CVE-2021-39226Готовый эксплойт | Snapshot authentication bypass in grafanagrafana · grafana · CWE-287 | Высокая7,3 | KEV | 99,9 % | 5 окт. 2021 г. |
89Срочно | CVE-2022-0847Готовый эксплойт | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Высокая7,8 | KEV | 92,8 % | 10 мар. 2022 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2015-3306100Срочно
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %proftpd · proftpd18 мая 2015 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2021-4177399Срочно
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server5 окт. 2021 г.
- CVE-2024-457799Срочно
Argument Injection in PHP-CGI
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php9 июн. 2024 г.
- CVE-2021-4201399Срочно
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server7 окт. 2021 г.
- CVE-2019-1104399Срочно
Underflow in PHP-FPM can lead to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php28 окт. 2019 г.
- CVE-2020-1684699Срочно
An issue was discovered in SaltStack Salt through 3002.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %saltstack · salt6 нояб. 2020 г.
- CVE-2020-193899Срочно
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · geode24 февр. 2020 г.
- CVE-2020-724799Срочно
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %openbsd · opensmtpd29 янв. 2020 г.
- CVE-2019-554498Срочно
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %openslp · openslp6 дек. 2019 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2023-486395Срочно
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %google · chrome12 сент. 2023 г.
- CVE-2021-3914493Срочно
XStream is vulnerable to a Remote Command Execution attack
ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 98 %xstream · xstream23 авг. 2021 г.
- CVE-2021-2220491Срочно
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing t
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %exiftool project · exiftool23 апр. 2021 г.
- CVE-2021-315691Срочно
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %sudo project · sudo26 янв. 2021 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2015-547790Срочно
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %isc · bind29 июл. 2015 г.
- CVE-2019-541890Срочно
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %rubyonrails · rails27 мар. 2019 г.
- CVE-2021-2122490Срочно
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 84 %google · chrome26 апр. 2021 г.
- CVE-2021-4402690Срочно
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %roundcube · webmail19 нояб. 2021 г.
- CVE-2021-3922689Срочно
Snapshot authentication bypass in grafana
ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 100 %grafana · grafana5 окт. 2021 г.
- CVE-2022-084789Срочно
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %linux · linux kernel10 мар. 2022 г.