Записи sybase
37 опубликованных записей вендора sybase.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 5,4 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-285 Improper Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2008-0912Proof of concept | Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10sybase · mobilink · CWE-119 | Критическая10,0 | — | 15,6 % | 22 февр. 2008 г. |
43В плане | CVE-2005-0441Эксплойта нет | Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users tsybase · adaptive server enterprise | Критическая10,0 | — | 8,5 % | 22 дек. 2004 г. |
42В плане | CVE-2002-2250Эксплойта нет | Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter sybase · adaptive server · CWE-119 | Критическая10,0 | — | 7,7 % | 31 дек. 2002 г. |
41В плане | CVE-2013-6245Эксплойта нет | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.sybase · adaptive server enterprise | Критическая10,0 | — | 4,7 % | 23 окт. 2013 г. |
41В плане | CVE-2011-0496Эксплойта нет | Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), asybase · appeon for powerbuilder | Критическая10,0 | — | 4,5 % | 20 янв. 2011 г. |
41В плане | CVE-2011-2475Эксплойта нет | Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybsybase · onebridge mobile data suite · CWE-134 | Критическая10,0 | — | 3,7 % | 9 июн. 2011 г. |
41В плане | CVE-2006-3667Эксплойта нет | Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vesybase · financial fusion consumer banking solution | Критическая10,0 | — | 1,7 % | 18 июл. 2006 г. |
40В плане | CVE-2005-2297Готовый эксплойт | Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary codsybase · easerver | Средняя4,6 | — | 74,2 % | 19 июл. 2005 г. |
39Наблюдать | CVE-2011-2474Готовый эксплойт | Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary fisybase · easerver · CWE-22 | Средняя5,0 | — | 63,6 % | 9 июн. 2011 г. |
39Наблюдать | CVE-2016-7402Эксплойта нет | SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system adminisybase · adaptive server enterprise · CWE-264 | Критическая9,8 | — | 1,1 % | 3 нояб. 2016 г. |
37Наблюдать | CVE-2013-6866Эксплойта нет | SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows sybase · adaptive server enterprise · CWE-94 | Критическая9,0 | — | 3,1 % | 23 нояб. 2013 г. |
37Наблюдать | CVE-2013-6865Эксплойта нет | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 sybase · adaptive server enterprise · CWE-94 | Критическая9,0 | — | 3,1 % | 23 нояб. 2013 г. |
37Наблюдать | CVE-2013-6863Эксплойта нет | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 sybase · adaptive server enterprise · CWE-264 | Критическая9,0 | — | 1,9 % | 23 нояб. 2013 г. |
34Наблюдать | CVE-2013-6859Эксплойта нет | SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.sybase · adaptive server enterprise · CWE-287 | Высокая8,5 | — | 1,6 % | 23 нояб. 2013 г. |
32Наблюдать | CVE-2011-0497Эксплойта нет | Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), asybase · appeon for powerbuilder · CWE-22 | Высокая7,8 | — | 2,2 % | 20 янв. 2011 г. |
31Наблюдать | CVE-2017-5371Эксплойта нет | Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series ofsybase · adaptive server enterprise · CWE-20 | Высокая7,5 | — | 3,8 % | 23 янв. 2017 г. |
31Наблюдать | CVE-2014-6284Эксплойта нет | SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and responssybase · adaptive server enterprise · CWE-264 | Высокая7,5 | — | 1,8 % | 8 июн. 2015 г. |
31Наблюдать | CVE-2013-6862Эксплойта нет | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15sybase · adaptive server enterprise | Высокая7,8 | — | 1,3 % | 23 нояб. 2013 г. |
31Наблюдать | CVE-2013-6868Эксплойта нет | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 sybase · adaptive server enterprise · CWE-200 | Высокая7,8 | — | 1,1 % | 23 нояб. 2013 г. |
30Наблюдать | CVE-2013-7245Эксплойта нет | The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dusybase · adaptive server enterprise · CWE-285 | Высокая7,5 | — | 1,4 % | 24 апр. 2018 г. |
30Наблюдать | CVE-2015-1310Эксплойта нет | SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary SQL commands via unssybase · adaptive server enterprise · CWE-89 | Высокая7,5 | — | 1,2 % | 22 янв. 2015 г. |
28Наблюдать | CVE-2013-6867Эксплойта нет | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to caussybase · adaptive server enterprise | Высокая7,1 | — | 1,5 % | 23 нояб. 2013 г. |
27Наблюдать | CVE-2013-6860Эксплойта нет | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15sybase · adaptive server enterprise | Средняя6,8 | — | 1,3 % | 23 нояб. 2013 г. |
26Наблюдать | CVE-2014-6283Эксплойта нет | SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict acsybase · adaptive server enterprise · CWE-264 | Средняя6,5 | — | 1,1 % | 17 окт. 2014 г. |
26Наблюдать | CVE-2011-5078Эксплойта нет | The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin sybase · m-business anywhere · CWE-264 | Средняя6,5 | — | 1,0 % | 8 февр. 2012 г. |
- CVE-2008-091245В плане
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10
КритическаяCVSS 10,0Proof of conceptEPSS 16 %sybase · mobilink22 февр. 2008 г.
- CVE-2005-044143В плане
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users t
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %sybase · adaptive server enterprise22 дек. 2004 г.
- CVE-2002-225042В плане
Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %sybase · adaptive server31 дек. 2002 г.
- CVE-2013-624541В плане
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %sybase · adaptive server enterprise23 окт. 2013 г.
- CVE-2011-049641В плане
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), a
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %sybase · appeon for powerbuilder20 янв. 2011 г.
- CVE-2011-247541В плане
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Syb
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %sybase · onebridge mobile data suite9 июн. 2011 г.
- CVE-2006-366741В плане
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack ve
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %sybase · financial fusion consumer banking solution18 июл. 2006 г.
- CVE-2005-229740В плане
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary cod
СредняяCVSS 4,6Готовый эксплойтEPSS 74 %sybase · easerver19 июл. 2005 г.
- CVE-2011-247439Наблюдать
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary fi
СредняяCVSS 5,0Готовый эксплойтEPSS 64 %sybase · easerver9 июн. 2011 г.
- CVE-2016-740239Наблюдать
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system admini
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sybase · adaptive server enterprise3 нояб. 2016 г.
- CVE-2013-686637Наблюдать
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2013-686537Наблюдать
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2013-686337Наблюдать
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2013-685934Наблюдать
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3.
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2011-049732Наблюдать
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %sybase · appeon for powerbuilder20 янв. 2011 г.
- CVE-2017-537131Наблюдать
Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %sybase · adaptive server enterprise23 янв. 2017 г.
- CVE-2014-628431Наблюдать
SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and respons
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sybase · adaptive server enterprise8 июн. 2015 г.
- CVE-2013-686231Наблюдать
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2013-686831Наблюдать
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2013-724530Наблюдать
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database du
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sybase · adaptive server enterprise24 апр. 2018 г.
- CVE-2015-131030Наблюдать
SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary SQL commands via uns
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sybase · adaptive server enterprise22 янв. 2015 г.
- CVE-2013-686728Наблюдать
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to caus
ВысокаяCVSS 7,1Эксплойта нетEPSS 2 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2013-686027Наблюдать
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15
СредняяCVSS 6,8Эксплойта нетEPSS 1 %sybase · adaptive server enterprise23 нояб. 2013 г.
- CVE-2014-628326Наблюдать
SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict ac
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sybase · adaptive server enterprise17 окт. 2014 г.
- CVE-2011-507826Наблюдать
The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sybase · m-business anywhere8 февр. 2012 г.