Записи upx
35 опубликованных записей вендора upx.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer21
- CWE-125 Out-of-bounds Read3
- CWE-476 NULL Pointer Dereference2
- CWE-190 Integer Overflow or Wraparound2
- CWE-415 Double Free1
- CWE-617 Reachable Assertion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
35 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-3209Эксплойта нет | UPX bele.h get_ne64 heap-based overflowupx · upx · CWE-122 | Критическая9,8 | — | 1,2 % | 2 апр. 2024 г. |
32Наблюдать | CVE-2018-11243Эксплойта нет | PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of upx · upx · CWE-415 | Высокая7,8 | — | 2,4 % | 18 мая 2018 г. |
32Наблюдать | CVE-2019-14296Эксплойта нет | canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) upx · upx · CWE-119 | Высокая7,8 | — | 1,8 % | 27 июл. 2019 г. |
31Наблюдать | CVE-2021-30500Эксплойта нет | Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0.upx · upx · CWE-476 | Высокая7,8 | — | 1,2 % | 26 мая 2021 г. |
31Наблюдать | CVE-2017-16869Эксплойта нет | p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have uupx · upx · CWE-119 | Высокая7,8 | — | 1,0 % | 17 нояб. 2017 г. |
31Наблюдать | CVE-2017-15056Эксплойта нет | p_lx_elf.cpp in UPX 3.94 mishandles ELF headers, which allows remote attackers to cause a denial of service (application crash) or possibly upx · upx · CWE-476 | Высокая7,8 | — | 1,0 % | 6 окт. 2017 г. |
31Наблюдать | CVE-2020-27801Эксплойта нет | A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.upx · upx · CWE-119 | Высокая7,8 | — | 0,4 % | 25 авг. 2022 г. |
31Наблюдать | CVE-2020-27796Эксплойта нет | A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.upx · upx · CWE-119 | Высокая7,8 | — | 0,3 % | 25 авг. 2022 г. |
31Наблюдать | CVE-2020-27800Эксплойта нет | A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.upx · upx · CWE-119 | Высокая7,8 | — | 0,3 % | 25 авг. 2022 г. |
31Наблюдать | CVE-2020-27799Эксплойта нет | A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.upx · upx · CWE-119 | Высокая7,8 | — | 0,3 % | 25 авг. 2022 г. |
30Наблюдать | CVE-2021-43312Эксплойта нет | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address.upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
30Наблюдать | CVE-2021-43317Эксплойта нет | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
30Наблюдать | CVE-2021-43316Эксплойта нет | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
30Наблюдать | CVE-2021-43315Эксплойта нет | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
30Наблюдать | CVE-2021-43314Эксплойта нет | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
30Наблюдать | CVE-2021-43313Эксплойта нет | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address.upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
30Наблюдать | CVE-2021-43311Эксплойта нет | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().upx · upx · CWE-119 | Высокая7,5 | — | 0,8 % | 24 мар. 2023 г. |
28Наблюдать | CVE-2020-24119Эксплойта нет | A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.upx · upx · CWE-125 | Высокая7,1 | — | 1,1 % | 14 мая 2021 г. |
26Наблюдать | CVE-2021-20285Эксплойта нет | A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96.upx · upx · CWE-119 | Средняя6,6 | — | 0,8 % | 26 мар. 2021 г. |
26Наблюдать | CVE-2021-46179Эксплойта нет | Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readxupx · upx · CWE-617 | Средняя6,5 | — | 0,5 % | 22 авг. 2023 г. |
22Наблюдать | CVE-2019-14295Эксплойта нет | An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) upx · upx · CWE-190 | Средняя5,5 | — | 1,5 % | 27 июл. 2019 г. |
22Наблюдать | CVE-2019-20053Эксплойта нет | An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.upx · upx · CWE-119 | Средняя5,5 | — | 1,2 % | 27 дек. 2019 г. |
22Наблюдать | CVE-2019-20021Эксплойта нет | A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.upx · upx · CWE-125 | Средняя5,5 | — | 1,1 % | 26 дек. 2019 г. |
22Наблюдать | CVE-2021-30501Эксплойта нет | An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0.upx · upx · CWE-20 | Средняя5,5 | — | 1,0 % | 26 мая 2021 г. |
22Наблюдать | CVE-2019-20051Эксплойта нет | A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95.upx · upx · CWE-682 | Средняя5,5 | — | 0,9 % | 27 дек. 2019 г. |
- CVE-2024-320939Наблюдать
UPX bele.h get_ne64 heap-based overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %upx · upx2 апр. 2024 г.
- CVE-2018-1124332Наблюдать
PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %upx · upx18 мая 2018 г.
- CVE-2019-1429632Наблюдать
canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash)
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %upx · upx27 июл. 2019 г.
- CVE-2021-3050031Наблюдать
Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %upx · upx26 мая 2021 г.
- CVE-2017-1686931Наблюдать
p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have u
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %upx · upx17 нояб. 2017 г.
- CVE-2017-1505631Наблюдать
p_lx_elf.cpp in UPX 3.94 mishandles ELF headers, which allows remote attackers to cause a denial of service (application crash) or possibly
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %upx · upx6 окт. 2017 г.
- CVE-2020-2780131Наблюдать
A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %upx · upx25 авг. 2022 г.
- CVE-2020-2779631Наблюдать
A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %upx · upx25 авг. 2022 г.
- CVE-2020-2780031Наблюдать
A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %upx · upx25 авг. 2022 г.
- CVE-2020-2779931Наблюдать
A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %upx · upx25 авг. 2022 г.
- CVE-2021-4331230Наблюдать
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2021-4331730Наблюдать
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2021-4331630Наблюдать
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2021-4331530Наблюдать
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2021-4331430Наблюдать
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2021-4331330Наблюдать
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2021-4331130Наблюдать
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %upx · upx24 мар. 2023 г.
- CVE-2020-2411928Наблюдать
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %upx · upx14 мая 2021 г.
- CVE-2021-2028526Наблюдать
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96.
СредняяCVSS 6,6Эксплойта нетEPSS 1 %upx · upx26 мар. 2021 г.
- CVE-2021-4617926Наблюдать
Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx
СредняяCVSS 6,5Эксплойта нетEPSS 1 %upx · upx22 авг. 2023 г.
- CVE-2019-1429522Наблюдать
An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash)
СредняяCVSS 5,5Эксплойта нетEPSS 2 %upx · upx27 июл. 2019 г.
- CVE-2019-2005322Наблюдать
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %upx · upx27 дек. 2019 г.
- CVE-2019-2002122Наблюдать
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %upx · upx26 дек. 2019 г.
- CVE-2021-3050122Наблюдать
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %upx · upx26 мая 2021 г.
- CVE-2019-2005122Наблюдать
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %upx · upx27 дек. 2019 г.