Записи zeromq
11 опубликованных записей вендора zeromq.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 90,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2019-13132Proof of concept | In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq applicatizeromq · libzmq · CWE-787 | Критическая9,8 | — | 41,6 % | 10 июл. 2019 г. |
45В плане | CVE-2021-20235Эксплойта нет | There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp.zeromq · libzmq · CWE-120 | Высокая8,1 | — | 43,9 % | 1 апр. 2021 г. |
40В плане | CVE-2020-36400Эксплойта нет | ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.zeromq · libzmq · CWE-787 | Критическая9,8 | — | 1,8 % | 30 июн. 2021 г. |
39Наблюдать | CVE-2021-20236Эксплойта нет | A flaw was found in the ZeroMQ server in versions before 4.3.3.zeromq · zeromq · CWE-120 | Критическая9,8 | — | 1,6 % | 28 мая 2021 г. |
38Наблюдать | CVE-2019-6250Proof of concept | A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1.zeromq · libzmq · CWE-190 | Высокая8,8 | — | 9,7 % | 13 янв. 2019 г. |
31Наблюдать | CVE-2020-15166Эксплойта нет | Denial of Service in ZeroMQzeromq · libzmq · CWE-400 | Высокая7,5 | — | 3,4 % | 11 сент. 2020 г. |
31Наблюдать | CVE-2021-20237Эксплойта нет | An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3.zeromq · libzmq · CWE-400 | Высокая7,5 | — | 1,7 % | 28 мая 2021 г. |
26Наблюдать | CVE-2021-20234Эксплойта нет | An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp.zeromq · libzmq · CWE-400 | Средняя6,5 | — | 1,1 % | 1 апр. 2021 г. |
18Наблюдать | CVE-2014-9721Эксплойта нет | libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanizeromq · zeromq · CWE-20 | Средняя4,3 | — | 2,5 % | 3 июн. 2015 г. |
18Наблюдать | CVE-2014-7202Эксплойта нет | stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a craftzeromq · zeromq | Средняя4,3 | — | 2,0 % | 8 окт. 2014 г. |
18Наблюдать | CVE-2014-7203Эксплойта нет | libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replazeromq · zeromq | Средняя4,3 | — | 1,9 % | 8 окт. 2014 г. |
- CVE-2019-1313251В плане
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq applicati
КритическаяCVSS 9,8Proof of conceptEPSS 42 %zeromq · libzmq10 июл. 2019 г.
- CVE-2021-2023545В плане
There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp.
ВысокаяCVSS 8,1Эксплойта нетEPSS 44 %zeromq · libzmq1 апр. 2021 г.
- CVE-2020-3640040В плане
ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zeromq · libzmq30 июн. 2021 г.
- CVE-2021-2023639Наблюдать
A flaw was found in the ZeroMQ server in versions before 4.3.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zeromq · zeromq28 мая 2021 г.
- CVE-2019-625038Наблюдать
A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %zeromq · libzmq13 янв. 2019 г.
- CVE-2020-1516631Наблюдать
Denial of Service in ZeroMQ
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %zeromq · libzmq11 сент. 2020 г.
- CVE-2021-2023731Наблюдать
An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %zeromq · libzmq28 мая 2021 г.
- CVE-2021-2023426Наблюдать
An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %zeromq · libzmq1 апр. 2021 г.
- CVE-2014-972118Наблюдать
libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechani
СредняяCVSS 4,3Эксплойта нетEPSS 3 %zeromq · zeromq3 июн. 2015 г.
- CVE-2014-720218Наблюдать
stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a craft
СредняяCVSS 4,3Эксплойта нетEPSS 2 %zeromq · zeromq8 окт. 2014 г.
- CVE-2014-720318Наблюдать
libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct repla
СредняяCVSS 4,3Эксплойта нетEPSS 2 %zeromq · zeromq8 окт. 2014 г.