Записи starwindsoftware
30 опубликованных записей вендора starwindsoftware.
Профиль для исследователя
- Попали в KEV
- 1 · 3,3 %
- С эксплойтом
- 1 · 3,3 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- 150 дн.
Повторяющиеся классы
- CWE-787 Out-of-bounds Write5
- CWE-287 Improper Authentication3
- CWE-125 Out-of-bounds Read3
- CWE-416 Use After Free2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-400 Uncontrolled Resource Consumption2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
30 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
89Срочно | CVE-2021-4034Готовый эксплойт | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Высокая7,8 | KEV | 94,3 % | 28 янв. 2022 г. |
44В плане | CVE-2021-43527Эксплойта нет | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-mozilla · nss · CWE-787 | Критическая9,8 | — | 17,6 % | 8 дек. 2021 г. |
39Наблюдать | CVE-2022-24552Эксплойта нет | A flaw was found in the REST API in StarWind Stack.starwindsoftware · nas · CWE-78 | Критическая9,8 | — | 1,3 % | 6 февр. 2022 г. |
39Наблюдать | CVE-2013-20004Эксплойта нет | A flaw was found in StarWind iSCSI target.starwindsoftware · iscsi san · CWE-400 | Критическая9,8 | — | 1,2 % | 6 февр. 2022 г. |
37Наблюдать | CVE-2021-42574Proof of concept | An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.unicode · unicode · CWE-94 | Высокая8,3 | — | 12,9 % | 1 нояб. 2021 г. |
36Наблюдать | CVE-2018-3839Эксплойта нет | An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.libsdl · sdl image · CWE-787 | Высокая8,8 | — | 2,6 % | 10 апр. 2018 г. |
36Наблюдать | CVE-2022-32268Эксплойта нет | StarWind SAN and NAS v0.2 build 1914 allow remote code execution.starwindsoftware · starwind san \& nas | Высокая8,8 | — | 2,3 % | 3 июн. 2022 г. |
35Наблюдать | CVE-2022-23858Эксплойта нет | A flaw was found in the REST API.starwindsoftware · command center | Высокая8,8 | — | 1,1 % | 23 янв. 2022 г. |
35Наблюдать | CVE-2022-24551Эксплойта нет | A flaw was found in StarWind Stack.starwindsoftware · nas · CWE-287 | Высокая8,8 | — | 0,9 % | 6 февр. 2022 г. |
31Наблюдать | CVE-2020-36385Эксплойта нет | An issue was discovered in the Linux kernel before 5.10.linux · linux kernel · CWE-416 | Высокая7,8 | — | 1,5 % | 7 июн. 2021 г. |
31Наблюдать | CVE-2020-14409Эксплойта нет | SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDlibsdl · simple directmedia layer · CWE-190 | Высокая7,8 | — | 1,3 % | 19 янв. 2021 г. |
30Наблюдать | CVE-2007-20001Эксплойта нет | A flaw was found in StarWind iSCSI target.starwindsoftware · iscsi san · CWE-400 | Высокая7,5 | — | 1,1 % | 6 февр. 2022 г. |
29Наблюдать | CVE-2020-25643Эксплойта нет | A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.linux · linux kernel · CWE-20 | Высокая7,2 | — | 3,3 % | 6 окт. 2020 г. |
29Наблюдать | CVE-2021-41617Proof of concept | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplementopenbsd · openssh | Высокая7,0 | — | 2,5 % | 26 сент. 2021 г. |
28Наблюдать | CVE-2021-20271Эксплойта нет | A flaw was found in RPM's signature check functionality when reading a package file.rpm · rpm · CWE-345 | Высокая7,0 | — | 0,8 % | 26 мар. 2021 г. |
28Наблюдать | CVE-2020-24394Эксплойта нет | In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesyslinux · linux kernel · CWE-732 | Высокая7,1 | — | 0,4 % | 19 авг. 2020 г. |
27Наблюдать | CVE-2018-18584Эксплойта нет | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quacabextract project · cabextract · CWE-787 | Средняя6,5 | — | 3,1 % | 22 окт. 2018 г. |
27Наблюдать | CVE-2021-37750Эксплойта нет | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/mit · kerberos 5 · CWE-476 | Средняя6,5 | — | 2,2 % | 23 авг. 2021 г. |
26Наблюдать | CVE-2021-42739Эксплойта нет | The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and driverslinux · linux kernel · CWE-787 | Средняя6,7 | — | 0,5 % | 20 окт. 2021 г. |
23Наблюдать | CVE-2018-16758Эксплойта нет | Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the tinc-vpn · tinc · CWE-306 | Средняя5,9 | — | 0,9 % | 10 окт. 2018 г. |
22Наблюдать | CVE-2018-3837Эксплойта нет | An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2libsdl · sdl image · CWE-125 | Средняя5,5 | — | 1,2 % | 10 апр. 2018 г. |
22Наблюдать | CVE-2020-0427Эксплойта нет | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.google · android · CWE-125 | Средняя5,5 | — | 0,5 % | 17 сент. 2020 г. |
22Наблюдать | CVE-2020-36322Эксплойта нет | An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.linux · linux kernel · CWE-459 | Средняя5,5 | — | 0,4 % | 14 апр. 2021 г. |
22Наблюдать | CVE-2020-14314Эксплойта нет | A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direclinux · linux kernel · CWE-125 | Средняя5,5 | — | 0,4 % | 15 сент. 2020 г. |
22Наблюдать | CVE-2020-25704Эксплойта нет | A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.linux · linux kernel · CWE-401 | Средняя5,5 | — | 0,4 % | 1 дек. 2020 г. |
- CVE-2021-403489Срочно
A local privilege escalation vulnerability was found on polkit's pkexec utility.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 94 %polkit project · polkit28 янв. 2022 г.
- CVE-2021-4352744В плане
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %mozilla · nss8 дек. 2021 г.
- CVE-2022-2455239Наблюдать
A flaw was found in the REST API in StarWind Stack.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %starwindsoftware · nas6 февр. 2022 г.
- CVE-2013-2000439Наблюдать
A flaw was found in StarWind iSCSI target.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %starwindsoftware · iscsi san6 февр. 2022 г.
- CVE-2021-4257437Наблюдать
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.
ВысокаяCVSS 8,3Proof of conceptEPSS 13 %unicode · unicode1 нояб. 2021 г.
- CVE-2018-383936Наблюдать
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %libsdl · sdl image10 апр. 2018 г.
- CVE-2022-3226836Наблюдать
StarWind SAN and NAS v0.2 build 1914 allow remote code execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %starwindsoftware · starwind san \& nas3 июн. 2022 г.
- CVE-2022-2385835Наблюдать
A flaw was found in the REST API.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %starwindsoftware · command center23 янв. 2022 г.
- CVE-2022-2455135Наблюдать
A flaw was found in StarWind Stack.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %starwindsoftware · nas6 февр. 2022 г.
- CVE-2020-3638531Наблюдать
An issue was discovered in the Linux kernel before 5.10.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %linux · linux kernel7 июн. 2021 г.
- CVE-2020-1440931Наблюдать
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SD
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %libsdl · simple directmedia layer19 янв. 2021 г.
- CVE-2007-2000130Наблюдать
A flaw was found in StarWind iSCSI target.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %starwindsoftware · iscsi san6 февр. 2022 г.
- CVE-2020-2564329Наблюдать
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %linux · linux kernel6 окт. 2020 г.
- CVE-2021-4161729Наблюдать
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplement
ВысокаяCVSS 7,0Proof of conceptEPSS 3 %openbsd · openssh26 сент. 2021 г.
- CVE-2021-2027128Наблюдать
A flaw was found in RPM's signature check functionality when reading a package file.
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %rpm · rpm26 мар. 2021 г.
- CVE-2020-2439428Наблюдать
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesys
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %linux · linux kernel19 авг. 2020 г.
- CVE-2018-1858427Наблюдать
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Qua
СредняяCVSS 6,5Эксплойта нетEPSS 3 %cabextract project · cabextract22 окт. 2018 г.
- CVE-2021-3775027Наблюдать
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/
СредняяCVSS 6,5Эксплойта нетEPSS 2 %mit · kerberos 523 авг. 2021 г.
- CVE-2021-4273926Наблюдать
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers
СредняяCVSS 6,7Эксплойта нетEPSS 0 %linux · linux kernel20 окт. 2021 г.
- CVE-2018-1675823Наблюдать
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the
СредняяCVSS 5,9Эксплойта нетEPSS 1 %tinc-vpn · tinc10 окт. 2018 г.
- CVE-2018-383722Наблюдать
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
СредняяCVSS 5,5Эксплойта нетEPSS 1 %libsdl · sdl image10 апр. 2018 г.
- CVE-2020-042722Наблюдать
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %google · android17 сент. 2020 г.
- CVE-2020-3632222Наблюдать
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel14 апр. 2021 г.
- CVE-2020-1431422Наблюдать
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direc
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel15 сент. 2020 г.
- CVE-2020-2570422Наблюдать
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel1 дек. 2020 г.