Записи trustwave
18 опубликованных записей вендора trustwave.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 61,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-255 Credentials Management Errors2
- CWE-476 NULL Pointer Dereference2
- CWE-170 Improper Null Termination1
- CWE-172 Encoding Error1
- CWE-306 Missing Authentication for Critical Function1
- CWE-436 Interpretation Conflict1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2017-18001Proof of concept | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorizetrustwave · secure web gateway · CWE-306 | Критическая9,8 | — | 13,8 % | 31 дек. 2017 г. |
40В плане | CVE-2014-2727Эксплойта нет | The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.trustwave · mailmarshal · CWE-78 | Критическая9,8 | — | 1,9 % | 19 февр. 2020 г. |
31Наблюдать | CVE-2013-1915Эксплойта нет | ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servitrustwave · modsecurity · CWE-611 | Высокая7,5 | — | 4,2 % | 25 апр. 2013 г. |
31Наблюдать | CVE-2021-42717Proof of concept | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.owasp · modsecurity · CWE-674 | Высокая7,5 | — | 3,1 % | 7 дек. 2021 г. |
31Наблюдать | CVE-2025-27110Эксплойта нет | Libmodsecurity3 has possible bypass of encoded HTML entitiestrustwave · modsecurity · CWE-172 | Высокая7,9 | — | 0,5 % | 25 февр. 2025 г. |
30Наблюдать | CVE-2022-48279Эксплойта нет | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewowasp · modsecurity · CWE-436 | Высокая7,5 | — | 1,2 % | 20 янв. 2023 г. |
30Наблюдать | CVE-2023-24021Эксплойта нет | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer overtrustwave · modsecurity · CWE-170 | Высокая7,5 | — | 0,9 % | 20 янв. 2023 г. |
30Наблюдать | CVE-2024-46292Эксплойта нет | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name paratrustwave · modsecurity · CWE-120 | Высокая7,5 | — | 0,8 % | 9 окт. 2024 г. |
30Наблюдать | CVE-2025-47947Эксплойта нет | ModSecurity Has Possible DoS Vulnerabilitytrustwave · modsecurity · CWE-1050 | Высокая7,5 | — | 0,6 % | 21 мая 2025 г. |
24Наблюдать | CVE-2009-1902Proof of concept | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapotrustwave · modsecurity · CWE-476 | Средняя5,0 | — | 13,7 % | 3 июн. 2009 г. |
24Наблюдать | CVE-2013-2765Proof of concept | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferencapache · http server · CWE-476 | Средняя5,0 | — | 13,7 % | 15 июл. 2013 г. |
24Наблюдать | CVE-2012-4528Proof of concept | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data totrustwave · modsecurity | Средняя5,0 | — | 12,5 % | 28 дек. 2012 г. |
21Наблюдать | CVE-2013-5705Эксплойта нет | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalizetrustwave · modsecurity | Средняя5,0 | — | 2,7 % | 15 апр. 2014 г. |
20Наблюдать | CVE-2011-1906Эксплойта нет | Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier ftrustwave · webdefend · CWE-255 | Средняя5,0 | — | 1,1 % | 5 мая 2011 г. |
20Наблюдать | CVE-2011-0756Эксплойта нет | The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote atttrustwave · webdefend · CWE-255 | Средняя5,0 | — | 1,1 % | 4 мая 2011 г. |
18Наблюдать | CVE-2012-2751Эксплойта нет | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in thtrustwave · modsecurity | Средняя4,3 | — | 3,3 % | 22 июл. 2012 г. |
18Наблюдать | CVE-2009-1903Эксплойта нет | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a rtrustwave · modsecurity | Средняя4,3 | — | 3,0 % | 3 июн. 2009 г. |
18Наблюдать | CVE-2009-5031Эксплойта нет | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteritrustwave · modsecurity · CWE-79 | Средняя4,3 | — | 2,9 % | 22 июл. 2012 г. |
- CVE-2017-1800143В плане
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorize
КритическаяCVSS 9,8Proof of conceptEPSS 14 %trustwave · secure web gateway31 дек. 2017 г.
- CVE-2014-272740В плане
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trustwave · mailmarshal19 февр. 2020 г.
- CVE-2013-191531Наблюдать
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %trustwave · modsecurity25 апр. 2013 г.
- CVE-2021-4271731Наблюдать
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %owasp · modsecurity7 дек. 2021 г.
- CVE-2025-2711031Наблюдать
Libmodsecurity3 has possible bypass of encoded HTML entities
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %trustwave · modsecurity25 февр. 2025 г.
- CVE-2022-4827930Наблюдать
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firew
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %owasp · modsecurity20 янв. 2023 г.
- CVE-2023-2402130Наблюдать
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %trustwave · modsecurity20 янв. 2023 г.
- CVE-2024-4629230Наблюдать
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name para
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %trustwave · modsecurity9 окт. 2024 г.
- CVE-2025-4794730Наблюдать
ModSecurity Has Possible DoS Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %trustwave · modsecurity21 мая 2025 г.
- CVE-2009-190224Наблюдать
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapo
СредняяCVSS 5,0Proof of conceptEPSS 14 %trustwave · modsecurity3 июн. 2009 г.
- CVE-2013-276524Наблюдать
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferenc
СредняяCVSS 5,0Proof of conceptEPSS 14 %apache · http server15 июл. 2013 г.
- CVE-2012-452824Наблюдать
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to
СредняяCVSS 5,0Proof of conceptEPSS 13 %trustwave · modsecurity28 дек. 2012 г.
- CVE-2013-570521Наблюдать
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalize
СредняяCVSS 5,0Эксплойта нетEPSS 3 %trustwave · modsecurity15 апр. 2014 г.
- CVE-2011-190620Наблюдать
Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier f
СредняяCVSS 5,0Эксплойта нетEPSS 1 %trustwave · webdefend5 мая 2011 г.
- CVE-2011-075620Наблюдать
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote att
СредняяCVSS 5,0Эксплойта нетEPSS 1 %trustwave · webdefend4 мая 2011 г.
- CVE-2012-275118Наблюдать
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in th
СредняяCVSS 4,3Эксплойта нетEPSS 3 %trustwave · modsecurity22 июл. 2012 г.
- CVE-2009-190318Наблюдать
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a r
СредняяCVSS 4,3Эксплойта нетEPSS 3 %trustwave · modsecurity3 июн. 2009 г.
- CVE-2009-503118Наблюдать
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteri
СредняяCVSS 4,3Эксплойта нетEPSS 3 %trustwave · modsecurity22 июл. 2012 г.