Записи OSSEC
12 опубликованных записей вендора ossec.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-416 Use After Free2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-674 Uncontrolled Recursion1
- CWE-787 Out-of-bounds Write1
- CWE-193 Off-by-one Error1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-8443Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-basossec · ossec · CWE-193 | Критическая9,8 | — | 2,7 % | 29 янв. 2020 г. |
40В плане | CVE-2020-8444Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durinossec · ossec · CWE-416 | Критическая9,8 | — | 2,5 % | 29 янв. 2020 г. |
40В плане | CVE-2020-8445Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlineossec · ossec · CWE-20 | Критическая9,8 | — | 2,3 % | 29 янв. 2020 г. |
40В плане | CVE-2020-8447Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durinossec · ossec · CWE-416 | Критическая9,8 | — | 1,9 % | 29 янв. 2020 г. |
36Наблюдать | CVE-2020-8442Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ovossec · ossec · CWE-787 | Высокая8,8 | — | 2,4 % | 29 янв. 2020 г. |
31Наблюдать | CVE-2018-19666Эксплойта нет | The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging fullossec · ossec · CWE-22 | Высокая7,8 | — | 0,8 % | 29 нояб. 2018 г. |
30Наблюдать | CVE-2021-28040Эксплойта нет | An issue was discovered in OSSEC 3.6.0.ossec · ossec · CWE-674 | Высокая7,5 | — | 1,2 % | 5 мар. 2021 г. |
29Наблюдать | CVE-2014-5284Proof of concept | host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local userossec · ossec · CWE-264 | Высокая7,2 | — | 2,4 % | 1 дек. 2014 г. |
29Наблюдать | CVE-2015-3222Proof of concept | syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.ossec · ossec · CWE-264 | Высокая7,0 | — | 2,0 % | 7 сент. 2017 г. |
24Наблюдать | CVE-2016-4847Эксплойта нет | Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scripossec · web ui · CWE-79 | Средняя6,1 | — | 1,3 % | 20 апр. 2017 г. |
22Наблюдать | CVE-2020-8446Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with wossec · ossec · CWE-22 | Средняя5,5 | — | 0,5 % | 29 янв. 2020 г. |
22Наблюдать | CVE-2020-8448Эксплойта нет | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (Nossec · ossec · CWE-476 | Средняя5,5 | — | 0,5 % | 29 янв. 2020 г. |
- CVE-2020-844340В плане
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ossec · ossec29 янв. 2020 г.
- CVE-2020-844440В плане
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ossec · ossec29 янв. 2020 г.
- CVE-2020-844540В плане
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newline
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ossec · ossec29 янв. 2020 г.
- CVE-2020-844740В плане
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ossec · ossec29 янв. 2020 г.
- CVE-2020-844236Наблюдать
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ov
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %ossec · ossec29 янв. 2020 г.
- CVE-2018-1966631Наблюдать
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %ossec · ossec29 нояб. 2018 г.
- CVE-2021-2804030Наблюдать
An issue was discovered in OSSEC 3.6.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ossec · ossec5 мар. 2021 г.
- CVE-2014-528429Наблюдать
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local user
ВысокаяCVSS 7,2Proof of conceptEPSS 2 %ossec · ossec1 дек. 2014 г.
- CVE-2015-322229Наблюдать
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
ВысокаяCVSS 7,0Proof of conceptEPSS 2 %ossec · ossec7 сент. 2017 г.
- CVE-2016-484724Наблюдать
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scrip
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ossec · web ui20 апр. 2017 г.
- CVE-2020-844622Наблюдать
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with w
СредняяCVSS 5,5Эксплойта нетEPSS 1 %ossec · ossec29 янв. 2020 г.
- CVE-2020-844822Наблюдать
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (N
СредняяCVSS 5,5Эксплойта нетEPSS 0 %ossec · ossec29 янв. 2020 г.