Записи openswan
6 опубликованных записей вендора openswan.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 16,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2004-0590Эксплойта нет | FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and stropenswan · openswan | Критическая10,0 | — | 2,8 % | 6 дек. 2004 г. |
33Наблюдать | CVE-2005-3671Эксплойта нет | The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.openswan · openswan | Высокая7,8 | — | 7,5 % | 18 нояб. 2005 г. |
29Наблюдать | CVE-2005-0162Эксплойта нет | Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x openswan · openswan | Высокая7,2 | — | 1,7 % | 26 янв. 2005 г. |
27Наблюдать | CVE-2008-4966Эксплойта нет | linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly#openswan · linux-patch-openswan · CWE-59 | Средняя6,9 | — | 0,4 % | 6 нояб. 2008 г. |
17Наблюдать | CVE-2008-4190Proof of concept | The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and executopenswan · openswan · CWE-59 | Средняя4,4 | — | 1,1 % | 24 сент. 2008 г. |
14Наблюдать | CVE-2011-2147Эксплойта нет | Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/openswan · openswan · CWE-264 | Низкая3,6 | — | 0,3 % | 20 мая 2011 г. |
- CVE-2004-059041В плане
FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and str
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %openswan · openswan6 дек. 2004 г.
- CVE-2005-367133Наблюдать
The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.
ВысокаяCVSS 7,8Эксплойта нетEPSS 7 %openswan · openswan18 нояб. 2005 г.
- CVE-2005-016229Наблюдать
Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %openswan · openswan26 янв. 2005 г.
- CVE-2008-496627Наблюдать
linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly#
СредняяCVSS 6,9Эксплойта нетEPSS 0 %openswan · linux-patch-openswan6 нояб. 2008 г.
- CVE-2008-419017Наблюдать
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execut
СредняяCVSS 4,4Proof of conceptEPSS 1 %openswan · openswan24 сент. 2008 г.
- CVE-2011-214714Наблюдать
Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %openswan · openswan20 мая 2011 г.