Записи Oculus
4 опубликованных записей вендора oculus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-269 Improper Privilege Management1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2021-28580Эксплойта нет | Medium by Adobe file parsing buffer overflow vulnerability could lead to arbitrary code executionadobe · medium · CWE-120 | Высокая7,8 | — | 8,5 % | 8 сент. 2021 г. |
31Наблюдать | CVE-2020-1885Эксплойта нет | Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users toculus · desktop · CWE-59 | Высокая7,8 | — | 0,4 % | 8 апр. 2020 г. |
31Наблюдать | CVE-2021-24038Эксплойта нет | Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged poculus · desktop · CWE-269 | Высокая7,8 | — | 0,2 % | 19 авг. 2021 г. |
24Наблюдать | CVE-2019-3562Эксплойта нет | A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute codeoculus · oculus browser · CWE-74 | Средняя6,1 | — | 1,1 % | 29 апр. 2019 г. |
- CVE-2021-2858034Наблюдать
Medium by Adobe file parsing buffer overflow vulnerability could lead to arbitrary code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 8 %adobe · medium8 сент. 2021 г.
- CVE-2020-188531Наблюдать
Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users t
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %oculus · desktop8 апр. 2020 г.
- CVE-2021-2403831Наблюдать
Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged p
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %oculus · desktop19 авг. 2021 г.
- CVE-2019-356224Наблюдать
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code
СредняяCVSS 6,1Эксплойта нетEPSS 1 %oculus · oculus browser29 апр. 2019 г.