Перейти к содержимому
Noroxi

Записи OSSEC

12 опубликованных записей вендора ossec.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 18
  3. 20
  4. 21

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

12 записей
  • CVE-2020-8443
    40В плане

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2020-8444
    40В плане

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2020-8445
    40В плане

    In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newline

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2020-8447
    40В плане

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2020-8442
    36Наблюдать

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ov

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2018-19666
    31Наблюдать

    The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    ossec · ossec29 нояб. 2018 г.

  • CVE-2021-28040
    30Наблюдать

    An issue was discovered in OSSEC 3.6.0.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ossec · ossec5 мар. 2021 г.

  • CVE-2014-5284
    29Наблюдать

    host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local user

    ВысокаяCVSS 7,2Proof of conceptEPSS 2 %

    ossec · ossec1 дек. 2014 г.

  • CVE-2015-3222
    29Наблюдать

    syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

    ВысокаяCVSS 7,0Proof of conceptEPSS 2 %

    ossec · ossec7 сент. 2017 г.

  • CVE-2016-4847
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scrip

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    ossec · web ui20 апр. 2017 г.

  • CVE-2020-8446
    22Наблюдать

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with w

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2020-8448
    22Наблюдать

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (N

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    ossec · ossec29 янв. 2020 г.