Записи varnish-cache
7 опубликованных записей вендора varnish-cache.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-190 Integer Overflow or Wraparound1
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
- CWE-476 NULL Pointer Dereference1
- CWE-617 Reachable Assertion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2017-8807Эксплойта нет | vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to ovarnish-cache · varnish · CWE-119 | Критическая9,1 | — | 4,1 % | 15 нояб. 2017 г. |
31Наблюдать | CVE-2017-12425Эксплойта нет | An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.varnish-cache · varnish · CWE-190 | Высокая7,5 | — | 2,4 % | 4 авг. 2017 г. |
31Наблюдать | CVE-2020-11653Эксплойта нет | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.varnish-cache · varnish cache · CWE-617 | Высокая7,5 | — | 2,2 % | 8 апр. 2020 г. |
31Наблюдать | CVE-2019-20637Эксплойта нет | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.varnish-cache · varnish cache · CWE-212 | Высокая7,5 | — | 1,8 % | 8 апр. 2020 г. |
30Наблюдать | CVE-2021-28543Эксплойта нет | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations.varnish-cache · varnish-modules · CWE-476 | Высокая7,5 | — | 1,5 % | 16 мар. 2021 г. |
26Наблюдать | CVE-2021-36740Эксплойта нет | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST requevarnish-cache · varnish cache · CWE-444 | Средняя6,5 | — | 1,6 % | 14 июл. 2021 г. |
21Наблюдать | CVE-2013-4484Эксплойта нет | Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET requevarnish-cache · varnish · CWE-119 | Средняя5,0 | — | 3,2 % | 31 окт. 2013 г. |
- CVE-2017-880737Наблюдать
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to o
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %varnish-cache · varnish15 нояб. 2017 г.
- CVE-2017-1242531Наблюдать
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish4 авг. 2017 г.
- CVE-2020-1165331Наблюдать
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache8 апр. 2020 г.
- CVE-2019-2063731Наблюдать
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache8 апр. 2020 г.
- CVE-2021-2854330Наблюдать
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %varnish-cache · varnish-modules16 мар. 2021 г.
- CVE-2021-3674026Наблюдать
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST reque
СредняяCVSS 6,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache14 июл. 2021 г.
- CVE-2013-448421Наблюдать
Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET reque
СредняяCVSS 5,0Эксплойта нетEPSS 3 %varnish-cache · varnish31 окт. 2013 г.