Записи keepalived
6 опубликованных записей вендора keepalived.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-19115Эксплойта нет | keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impackeepalived · keepalived · CWE-787 | Критическая9,8 | — | 3,7 % | 8 нояб. 2018 г. |
31Наблюдать | CVE-2018-19045Эксплойта нет | keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive infokeepalived · keepalived · CWE-200 | Высокая7,5 | — | 2,4 % | 8 нояб. 2018 г. |
21Наблюдать | CVE-2021-44225Эксплойта нет | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipkeepalived · keepalived | Средняя5,4 | — | 1,1 % | 25 нояб. 2021 г. |
18Наблюдать | CVE-2018-19044Эксплойта нет | keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats.keepalived · keepalived · CWE-59 | Средняя4,7 | — | 0,5 % | 8 нояб. 2018 г. |
18Наблюдать | CVE-2018-19046Эксплойта нет | keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats.keepalived · keepalived · CWE-200 | Средняя4,7 | — | 0,4 % | 8 нояб. 2018 г. |
14Наблюдать | CVE-2011-1784Эксплойта нет | The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.keepalived · keepalived · CWE-264 | Низкая3,6 | — | 0,4 % | 20 мая 2011 г. |
- CVE-2018-1911540В плане
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impac
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %keepalived · keepalived8 нояб. 2018 г.
- CVE-2018-1904531Наблюдать
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive info
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %keepalived · keepalived8 нояб. 2018 г.
- CVE-2021-4422521Наблюдать
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manip
СредняяCVSS 5,4Эксплойта нетEPSS 1 %keepalived · keepalived25 нояб. 2021 г.
- CVE-2018-1904418Наблюдать
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats.
СредняяCVSS 4,7Эксплойта нетEPSS 1 %keepalived · keepalived8 нояб. 2018 г.
- CVE-2018-1904618Наблюдать
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats.
СредняяCVSS 4,7Эксплойта нетEPSS 0 %keepalived · keepalived8 нояб. 2018 г.
- CVE-2011-178414Наблюдать
The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %keepalived · keepalived20 мая 2011 г.