Записи Intel
1 868 опубликованных записей вендора intel.
Профиль для исследователя
- Попали в KEV
- 4 · 0,2 %
- С эксплойтом
- 5 · 0,3 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 9,6 %
- Медиана: публикация → KEV
- 1118 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation272
- CWE-427 Uncontrolled Search Path Element162
- CWE-284 Improper Access Control106
- CWE-276 Incorrect Default Permissions87
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer71
- CWE-787 Out-of-bounds Write68
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
1 868 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
97Срочно | CVE-2017-5689Готовый эксплойт | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Критическая9,8 | KEV | 92,2 % | 2 мая 2017 г. |
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
64На этой неделе | CVE-2015-2291Готовый эксплойт | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cintel · ethernet diagnostics driver iqvw32.sys · CWE-20 | Высокая7,8 | KEV | 9,0 % | 9 авг. 2017 г. |
54В плане | CVE-2013-4786Готовый эксплойт | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtainoracle · fujitsu m10 firmware · CWE-255 | Высокая7,5 | — | 78,6 % | 8 июл. 2013 г. |
51В плане | CVE-2024-22476Proof of concept | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially CWE-20 | Критическая10,0 | — | 36,0 % | 16 мая 2024 г. |
50В плане | CVE-2017-5753Proof of concept | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an atintel · atom c · CWE-203 | Средняя5,6 | — | 93,8 % | 4 янв. 2018 г. |
47В плане | CVE-2017-5754Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-200 | Средняя5,6 | — | 84,2 % | 4 янв. 2018 г. |
44В плане | CVE-2017-5715Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-203 | Средняя5,6 | — | 74,0 % | 4 янв. 2018 г. |
42В плане | CVE-2000-0384Proof of concept | NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructureintel · netstructure 7110 | Критическая10,0 | — | 5,9 % | 8 мая 2000 г. |
41В плане | CVE-2009-1385Эксплойта нет | Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30linux · kernel · CWE-189 | Высокая7,8 | — | 33,7 % | 4 июн. 2009 г. |
41В плане | CVE-2017-12865Proof of concept | Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execintel · connman · CWE-119 | Критическая9,8 | — | 5,5 % | 29 авг. 2017 г. |
40В плане | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Средняя5,5 | — | 60,6 % | 22 мая 2018 г. |
40В плане | CVE-2020-0594Эксплойта нет | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an uintel · active management technology firmware · CWE-125 | Критическая9,8 | — | 3,5 % | 15 июн. 2020 г. |
40В плане | CVE-2020-0595Эксплойта нет | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unautintel · active management technology firmware · CWE-416 | Критическая9,8 | — | 3,4 % | 15 июн. 2020 г. |
40В плане | CVE-2022-32292Эксплойта нет | In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow intel · connman · CWE-787 | Критическая9,8 | — | 3,2 % | 3 авг. 2022 г. |
40В плане | CVE-2020-11486Эксплойта нет | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwarenvidia · dgx-1 · CWE-434 | Критическая9,8 | — | 2,7 % | 29 окт. 2020 г. |
40В плане | CVE-2021-33833Эксплойта нет | ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTintel · connection manager · CWE-787 | Критическая9,8 | — | 2,6 % | 9 июн. 2021 г. |
40В плане | CVE-2019-0172Эксплойта нет | A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privintel · unite | Критическая9,8 | — | 2,3 % | 17 мая 2019 г. |
40В плане | CVE-2018-12171Эксплойта нет | Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to intel · bmc firmware | Критическая9,8 | — | 2,1 % | 12 сент. 2018 г. |
40В плане | CVE-2019-11119Эксплойта нет | Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentialintel · raid web console 3 | Критическая9,8 | — | 2,0 % | 13 июн. 2019 г. |
40В плане | CVE-2020-8758Эксплойта нет | Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, intel · standard manageability | Критическая9,8 | — | 1,9 % | 10 сент. 2020 г. |
40В плане | CVE-2019-0153Эксплойта нет | Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of pintel · converged security management engine firmware · CWE-119 | Критическая9,8 | — | 1,9 % | 17 мая 2019 г. |
40В плане | CVE-2019-0101Эксплойта нет | Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalaintel · unite | Критическая9,8 | — | 1,8 % | 18 февр. 2019 г. |
40В плане | CVE-2019-11131Эксплойта нет | Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentintel · active management technology firmware | Критическая9,8 | — | 1,8 % | 18 дек. 2019 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2017-568997Срочно
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %intel · active management technology firmware2 мая 2017 г.
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2015-229164На этой неделе
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to c
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 9 %intel · ethernet diagnostics driver iqvw32.sys9 авг. 2017 г.
- CVE-2013-478654В плане
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %oracle · fujitsu m10 firmware8 июл. 2013 г.
- CVE-2024-2247651В плане
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially
КритическаяCVSS 10,0Proof of conceptEPSS 36 %16 мая 2024 г.
- CVE-2017-575350В плане
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at
СредняяCVSS 5,6Proof of conceptEPSS 94 %intel · atom c4 янв. 2018 г.
- CVE-2017-575447В плане
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
СредняяCVSS 5,6Proof of conceptEPSS 84 %intel · atom c4 янв. 2018 г.
- CVE-2017-571544В плане
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
СредняяCVSS 5,6Proof of conceptEPSS 74 %intel · atom c4 янв. 2018 г.
- CVE-2000-038442В плане
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure
КритическаяCVSS 10,0Proof of conceptEPSS 6 %intel · netstructure 71108 мая 2000 г.
- CVE-2009-138541В плане
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30
ВысокаяCVSS 7,8Эксплойта нетEPSS 34 %linux · kernel4 июн. 2009 г.
- CVE-2017-1286541В плане
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or exec
КритическаяCVSS 9,8Proof of conceptEPSS 6 %intel · connman29 авг. 2017 г.
- CVE-2018-363940В плане
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
СредняяCVSS 5,5Proof of conceptEPSS 61 %intel · atom c22 мая 2018 г.
- CVE-2020-059440В плане
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an u
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %intel · active management technology firmware15 июн. 2020 г.
- CVE-2020-059540В плане
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unaut
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %intel · active management technology firmware15 июн. 2020 г.
- CVE-2022-3229240В плане
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %intel · connman3 авг. 2022 г.
- CVE-2020-1148640В плане
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nvidia · dgx-129 окт. 2020 г.
- CVE-2021-3383340В плане
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGT
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %intel · connection manager9 июн. 2021 г.
- CVE-2019-017240В плане
A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of priv
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · unite17 мая 2019 г.
- CVE-2018-1217140В плане
Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · bmc firmware12 сент. 2018 г.
- CVE-2019-1111940В плане
Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potential
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · raid web console 313 июн. 2019 г.
- CVE-2020-875840В плане
Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · standard manageability10 сент. 2020 г.
- CVE-2019-015340В плане
Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of p
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · converged security management engine firmware17 мая 2019 г.
- CVE-2019-010140В плане
Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escala
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · unite18 февр. 2019 г.
- CVE-2019-1113140В плане
Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potent
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %intel · active management technology firmware18 дек. 2019 г.