Записи openslp
9 опубликованных записей вендора openslp.
Профиль для исследователя
- Попали в KEV
- 1 · 11,1 %
- С эксплойтом
- 1 · 11,1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 77,8 %
- Медиана: публикация → KEV
- 698 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-415 Double Free1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2019-5544Готовый эксплойт | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Критическая9,8 | KEV | 97,3 % | 6 дек. 2019 г. |
43В плане | CVE-2016-7567Proof of concept | Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact openslp · openslp · CWE-119 | Критическая9,8 | — | 12,5 % | 23 янв. 2017 г. |
40В плане | CVE-2017-17833Эксплойта нет | OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-seopenslp · openslp · CWE-119 | Критическая9,8 | — | 3,8 % | 23 апр. 2018 г. |
33Наблюдать | CVE-2012-4428Эксплойта нет | openslp: SLPIntersectStringList()' Function has a DoS vulnerabilityopenslp · openslp · CWE-125 | Высокая7,5 | — | 9,6 % | 2 дек. 2019 г. |
32Наблюдать | CVE-2015-5177Эксплойта нет | Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial oopenslp · openslp · CWE-415 | Высокая7,5 | — | 6,3 % | 22 окт. 2017 г. |
32Наблюдать | CVE-2016-4912Эксплойта нет | The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference andopenslp · openslp · CWE-476 | Высокая7,5 | — | 5,4 % | 27 мар. 2017 г. |
31Наблюдать | CVE-2005-0769Эксплойта нет | Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.openslp · openslp | Высокая7,5 | — | 2,6 % | 2 мая 2005 г. |
25Наблюдать | CVE-2010-3609Proof of concept | The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol openslp · openslp | Средняя5,0 | — | 17,2 % | 11 мар. 2011 г. |
8Наблюдать | CVE-2003-0875Эксплойта нет | Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via topenslp · openslp | Низкая2,1 | — | 0,3 % | 17 нояб. 2003 г. |
- CVE-2019-554498Срочно
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %openslp · openslp6 дек. 2019 г.
- CVE-2016-756743В плане
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact
КритическаяCVSS 9,8Proof of conceptEPSS 12 %openslp · openslp23 янв. 2017 г.
- CVE-2017-1783340В плане
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-se
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %openslp · openslp23 апр. 2018 г.
- CVE-2012-442833Наблюдать
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %openslp · openslp2 дек. 2019 г.
- CVE-2015-517732Наблюдать
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial o
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %openslp · openslp22 окт. 2017 г.
- CVE-2016-491232Наблюдать
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %openslp · openslp27 мар. 2017 г.
- CVE-2005-076931Наблюдать
Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openslp · openslp2 мая 2005 г.
- CVE-2010-360925Наблюдать
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol
СредняяCVSS 5,0Proof of conceptEPSS 17 %openslp · openslp11 мар. 2011 г.
- CVE-2003-08758Наблюдать
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via t
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %openslp · openslp17 нояб. 2003 г.