Записи varnish-software
13 опубликованных записей вендора varnish-software.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 69,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
- CWE-617 Reachable Assertion2
- CWE-180 Incorrect Behavior Order: Validate Before Canonicalize1
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-34475Эксплойта нет | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / varnish-software · varnish enterprise · CWE-180 | Критическая9,8 | — | 0,4 % | 27 мар. 2026 г. |
37Наблюдать | CVE-2022-23959Эксплойта нет | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x beforvarnish-software · varnich cache · CWE-444 | Критическая9,1 | — | 2,0 % | 25 янв. 2022 г. |
32Наблюдать | CVE-2019-15892Эксплойта нет | An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1.varnish-software · varnish cache · CWE-617 | Высокая7,5 | — | 5,8 % | 3 сент. 2019 г. |
31Наблюдать | CVE-2017-12425Эксплойта нет | An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.varnish-cache · varnish · CWE-190 | Высокая7,5 | — | 2,4 % | 4 авг. 2017 г. |
31Наблюдать | CVE-2020-11653Эксплойта нет | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.varnish-cache · varnish cache · CWE-617 | Высокая7,5 | — | 2,2 % | 8 апр. 2020 г. |
31Наблюдать | CVE-2019-20637Эксплойта нет | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.varnish-cache · varnish cache · CWE-212 | Высокая7,5 | — | 1,8 % | 8 апр. 2020 г. |
30Наблюдать | CVE-2022-45060Эксплойта нет | An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1.varnish-software · varnish cache · CWE-20 | Высокая7,5 | — | 1,0 % | 9 нояб. 2022 г. |
30Наблюдать | CVE-2026-40394Эксплойта нет | Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certvarnish-software · varnish enterprise · CWE-670 | Высокая7,5 | — | 0,4 % | 12 апр. 2026 г. |
30Наблюдать | CVE-2026-40395Эксплойта нет | Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL.varnish-software · varnish enterprise · CWE-770 | Высокая7,5 | — | 0,4 % | 12 апр. 2026 г. |
30Наблюдать | CVE-2025-30347Эксплойта нет | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on varnish-software · varnish enterprise · CWE-125 | Высокая7,5 | — | 0,3 % | 21 мар. 2025 г. |
26Наблюдать | CVE-2021-36740Эксплойта нет | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST requevarnish-cache · varnish cache · CWE-444 | Средняя6,5 | — | 1,6 % | 14 июл. 2021 г. |
26Наблюдать | CVE-2023-41104Эксплойта нет | libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding,varnish-software · varnish enterprise · CWE-119 | Средняя6,5 | — | 0,6 % | 23 авг. 2023 г. |
19Наблюдать | CVE-2025-30346Эксплойта нет | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.varnish-software · varnish enterprise · CWE-444 | Средняя4,8 | — | 0,3 % | 21 мар. 2025 г. |
- CVE-2026-3447539Наблюдать
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %varnish-software · varnish enterprise27 мар. 2026 г.
- CVE-2022-2395937Наблюдать
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x befor
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %varnish-software · varnich cache25 янв. 2022 г.
- CVE-2019-1589232Наблюдать
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %varnish-software · varnish cache3 сент. 2019 г.
- CVE-2017-1242531Наблюдать
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish4 авг. 2017 г.
- CVE-2020-1165331Наблюдать
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache8 апр. 2020 г.
- CVE-2019-2063731Наблюдать
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache8 апр. 2020 г.
- CVE-2022-4506030Наблюдать
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %varnish-software · varnish cache9 нояб. 2022 г.
- CVE-2026-4039430Наблюдать
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for cert
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %varnish-software · varnish enterprise12 апр. 2026 г.
- CVE-2026-4039530Наблюдать
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %varnish-software · varnish enterprise12 апр. 2026 г.
- CVE-2025-3034730Наблюдать
Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %varnish-software · varnish enterprise21 мар. 2025 г.
- CVE-2021-3674026Наблюдать
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST reque
СредняяCVSS 6,5Эксплойта нетEPSS 2 %varnish-cache · varnish cache14 июл. 2021 г.
- CVE-2023-4110426Наблюдать
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding,
СредняяCVSS 6,5Эксплойта нетEPSS 1 %varnish-software · varnish enterprise23 авг. 2023 г.
- CVE-2025-3034619Наблюдать
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
СредняяCVSS 4,8Эксплойта нетEPSS 0 %varnish-software · varnish enterprise21 мар. 2025 г.