Записи redislabs
26 опубликованных записей вендора redislabs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,8 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 80,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-476 NULL Pointer Dereference3
- CWE-787 Out-of-bounds Write3
- CWE-20 Improper Input Validation2
- CWE-121 Stack-based Buffer Overflow1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2018-11218Готовый эксплойт | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 redislabs · redis · CWE-787 | Критическая9,8 | — | 59,0 % | 17 июн. 2018 г. |
43В плане | CVE-2016-8339Эксплойта нет | A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.redislabs · redis · CWE-787 | Критическая9,8 | — | 14,8 % | 28 окт. 2016 г. |
43В плане | CVE-2015-4335Эксплойта нет | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.redislabs · redis · CWE-17 | Критическая10,0 | — | 9,5 % | 9 июн. 2015 г. |
41В плане | CVE-2018-11219Эксплойта нет | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x beforredislabs · redis · CWE-190 | Критическая9,8 | — | 7,0 % | 17 июн. 2018 г. |
40В плане | CVE-2017-15047Эксплойта нет | The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and applredislabs · redis · CWE-119 | Критическая9,8 | — | 1,8 % | 6 окт. 2017 г. |
39Наблюдать | CVE-2021-32761Эксплойта нет | Integer overflow issues with *BIT commands on 32-bit systemsredislabs · redis · CWE-125 | Высокая7,5 | — | 31,2 % | 21 июл. 2021 г. |
39Наблюдать | CVE-2023-47003Эксплойта нет | An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlocredislabs · redisgraph · CWE-476 | Критическая9,8 | — | 1,1 % | 16 нояб. 2023 г. |
37Наблюдать | CVE-2018-12453Proof of concept | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-seredislabs · redis · CWE-704 | Высокая7,5 | — | 23,9 % | 16 июн. 2018 г. |
36Наблюдать | CVE-2019-10192Эксплойта нет | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.xredislabs · redis · CWE-122 | Высокая7,2 | — | 26,0 % | 11 июл. 2019 г. |
36Наблюдать | CVE-2021-21309Эксплойта нет | Integer overflow on 32-bit systemsredislabs · redis · CWE-190 | Высокая8,8 | — | 4,8 % | 26 февр. 2021 г. |
36Наблюдать | CVE-2021-32625Эксплойта нет | Redis vulnerability in STRALGO LCS on 32-bit systemsredislabs · redis · CWE-680 | Высокая8,8 | — | 4,1 % | 2 июн. 2021 г. |
36Наблюдать | CVE-2021-29477Эксплойта нет | Vulnerability in the STRALGO LCS commandredislabs · redis · CWE-190 | Высокая8,8 | — | 4,0 % | 4 мая 2021 г. |
36Наблюдать | CVE-2021-29478Эксплойта нет | Vulnerability in the COPY command for large intsetsredislabs · redis · CWE-190 | Высокая8,8 | — | 3,6 % | 4 мая 2021 г. |
35Наблюдать | CVE-2019-10193Эксплойта нет | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.redislabs · redis · CWE-121 | Высокая7,2 | — | 23,7 % | 11 июл. 2019 г. |
35Наблюдать | CVE-2023-47004Эксплойта нет | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code redislabs · redisgraph · CWE-787 | Высокая8,8 | — | 1,0 % | 6 нояб. 2023 г. |
34Наблюдать | CVE-2018-12326Proof of concept | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to highredislabs · redis · CWE-119 | Высокая8,4 | — | 2,7 % | 17 июн. 2018 г. |
31Наблюдать | CVE-2015-8080Эксплойта нет | Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackeredislabs · redis · CWE-190 | Высокая7,5 | — | 4,6 % | 13 апр. 2016 г. |
31Наблюдать | CVE-2020-14147Эксплойта нет | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lredislabs · redis · CWE-190 | Высокая7,7 | — | 3,1 % | 15 июн. 2020 г. |
31Наблюдать | CVE-2020-7105Эксплойта нет | async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.redislabs · hiredis · CWE-476 | Высокая7,5 | — | 2,7 % | 16 янв. 2020 г. |
30Наблюдать | CVE-2016-10517Эксплойта нет | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valiredislabs · redis · CWE-254 | Высокая7,4 | — | 2,1 % | 24 окт. 2017 г. |
30Наблюдать | CVE-2020-35668Эксплойта нет | RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as redislabs · redisgraph · CWE-476 | Высокая7,5 | — | 1,6 % | 23 дек. 2020 г. |
30Наблюдать | CVE-2020-21468Эксплойта нет | A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).redislabs · redis | Высокая7,5 | — | 1,2 % | 20 сент. 2021 г. |
22Наблюдать | CVE-2013-0178Эксплойта нет | Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.redislabs · redis · CWE-20 | Средняя5,5 | — | 0,4 % | 1 нояб. 2019 г. |
22Наблюдать | CVE-2013-0180Эксплойта нет | Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.redislabs · redis · CWE-20 | Средняя5,5 | — | 0,3 % | 1 нояб. 2019 г. |
21Наблюдать | CVE-2021-3470Эксплойта нет | A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemredislabs · redis · CWE-119 | Средняя5,3 | — | 1,1 % | 31 мар. 2021 г. |
- CVE-2018-1121857В плане
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0
КритическаяCVSS 9,8Готовый эксплойтEPSS 59 %redislabs · redis17 июн. 2018 г.
- CVE-2016-833943В плане
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %redislabs · redis28 окт. 2016 г.
- CVE-2015-433543В плане
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %redislabs · redis9 июн. 2015 г.
- CVE-2018-1121941В плане
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x befor
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %redislabs · redis17 июн. 2018 г.
- CVE-2017-1504740В плане
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and appl
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %redislabs · redis6 окт. 2017 г.
- CVE-2021-3276139Наблюдать
Integer overflow issues with *BIT commands on 32-bit systems
ВысокаяCVSS 7,5Эксплойта нетEPSS 31 %redislabs · redis21 июл. 2021 г.
- CVE-2023-4700339Наблюдать
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBloc
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redislabs · redisgraph16 нояб. 2023 г.
- CVE-2018-1245337Наблюдать
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-se
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %redislabs · redis16 июн. 2018 г.
- CVE-2019-1019236Наблюдать
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x
ВысокаяCVSS 7,2Эксплойта нетEPSS 26 %redislabs · redis11 июл. 2019 г.
- CVE-2021-2130936Наблюдать
Integer overflow on 32-bit systems
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %redislabs · redis26 февр. 2021 г.
- CVE-2021-3262536Наблюдать
Redis vulnerability in STRALGO LCS on 32-bit systems
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %redislabs · redis2 июн. 2021 г.
- CVE-2021-2947736Наблюдать
Vulnerability in the STRALGO LCS command
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %redislabs · redis4 мая 2021 г.
- CVE-2021-2947836Наблюдать
Vulnerability in the COPY command for large intsets
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %redislabs · redis4 мая 2021 г.
- CVE-2019-1019335Наблюдать
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.
ВысокаяCVSS 7,2Эксплойта нетEPSS 24 %redislabs · redis11 июл. 2019 г.
- CVE-2023-4700435Наблюдать
Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %redislabs · redisgraph6 нояб. 2023 г.
- CVE-2018-1232634Наблюдать
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to high
ВысокаяCVSS 8,4Proof of conceptEPSS 3 %redislabs · redis17 июн. 2018 г.
- CVE-2015-808031Наблюдать
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attacke
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %redislabs · redis13 апр. 2016 г.
- CVE-2020-1414731Наблюдать
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run L
ВысокаяCVSS 7,7Эксплойта нетEPSS 3 %redislabs · redis15 июн. 2020 г.
- CVE-2020-710531Наблюдать
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %redislabs · hiredis16 янв. 2020 г.
- CVE-2016-1051730Наблюдать
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not vali
ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %redislabs · redis24 окт. 2017 г.
- CVE-2020-3566830Наблюдать
RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redislabs · redisgraph23 дек. 2020 г.
- CVE-2020-2146830Наблюдать
A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redislabs · redis20 сент. 2021 г.
- CVE-2013-017822Наблюдать
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %redislabs · redis1 нояб. 2019 г.
- CVE-2013-018022Наблюдать
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %redislabs · redis1 нояб. 2019 г.
- CVE-2021-347021Наблюдать
A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jem
СредняяCVSS 5,3Эксплойта нетEPSS 1 %redislabs · redis31 мар. 2021 г.