CWE-254 · 379 kayıt
7PK - Security Features
Bu sınıftaki CVE’ler
379 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2016-2296Silahlaştırılmış | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remmeteocontrol · web\'log basic 100 · CWE-254 | Kritik9,4 | — | %64,3 | 14 May 2016 |
49Planlayın | CVE-2015-1158Kavram kanıtı | The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-cups · cups · CWE-254 | Kritik10,0 | — | %29,9 | 26 Haz 2015 |
47Planlayın | CVE-2016-0161İstismar yok | Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege microsoft · edge · CWE-254 | Orta6,5 | — | %68,8 | 12 Nis 2016 |
45Planlayın | CVE-2015-1793Silahlaştırılmış | The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic openssl · openssl · CWE-254 | Orta6,5 | — | %62,4 | 9 Tem 2015 |
43Planlayın | CVE-2016-3238Kavram kanıtı | The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201microsoft · windows 10 · CWE-254 | Yüksek8,1 | — | %35,4 | 12 Tem 2016 |
41Planlayın | CVE-2016-2118Kavram kanıtı | The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCsamba · samba · CWE-254 | Yüksek7,5 | — | %36,9 | 12 Nis 2016 |
41Planlayın | CVE-2016-10178İstismar yok | An issue was discovered on the D-Link DWR-932B router.dlink · dwr-932b firmware · CWE-254 | Kritik9,8 | — | %7,3 | 30 Oca 2017 |
41Planlayın | CVE-2016-6957İstismar yok | Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continadobe · acrobat · CWE-254 | Kritik9,8 | — | %5,8 | 13 Eki 2016 |
41Planlayın | CVE-2016-4215İstismar yok | Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continadobe · acrobat · CWE-254 | Kritik9,8 | — | %5,7 | 12 Tem 2016 |
41Planlayın | CVE-2014-5334İstismar yok | FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.freenas · freenas · CWE-254 | Kritik9,8 | — | %5,1 | 8 Oca 2018 |
41Planlayın | CVE-2015-3972İstismar yok | The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easiejanitza · umg 508 · CWE-254 | Kritik10,0 | — | %2,9 | 28 Eki 2015 |
41Planlayın | CVE-2016-5788İstismar yok | General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it ge · bently nevada 3500\/22m usb firmware · CWE-254 | Kritik10,0 | — | %2,3 | 24 Kas 2016 |
40Planlayın | CVE-2015-8286İstismar yok | Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP porzhuhai · raysharp firmware · CWE-254 | Kritik9,8 | — | %4,6 | 18 Şub 2016 |
40Planlayın | CVE-2015-8803İstismar yok | The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its nettle project · nettle · CWE-254 | Kritik9,8 | — | %4,2 | 23 Şub 2016 |
40Planlayın | CVE-2015-7554İstismar yok | The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or libtiff · libtiff · CWE-254 | Kritik9,8 | — | %4,2 | 8 Oca 2016 |
40Planlayın | CVE-2017-8227İstismar yok | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are deamcrest · ipm-721s firmware · CWE-254 | Kritik9,8 | — | %4,1 | 3 Tem 2019 |
40Planlayın | CVE-2015-8804İstismar yok | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation nettle project · nettle · CWE-254 | Kritik9,8 | — | %3,9 | 23 Şub 2016 |
40Planlayın | CVE-2015-8857İstismar yok | The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which muglifyjs project · uglifyjs · CWE-254 | Kritik9,8 | — | %3,6 | 23 Oca 2017 |
40Planlayın | CVE-2015-6473İstismar yok | WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.wago · 750-849 firmware · CWE-254 | Kritik9,8 | — | %3,5 | 22 Ağu 2017 |
40Planlayın | CVE-2016-1896İstismar yok | Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0lexmark · printer firmware · CWE-254 | Kritik9,8 | — | %3,3 | 27 Oca 2016 |
40Planlayın | CVE-2016-6629İstismar yok | An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive.phpmyadmin · phpmyadmin · CWE-254 | Kritik9,8 | — | %3,2 | 10 Ara 2016 |
40Planlayın | CVE-2011-4889İstismar yok | The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before ibm · websphere application server · CWE-254 | Kritik9,8 | — | %2,7 | 8 Şub 2018 |
40Planlayın | CVE-2016-10321İstismar yok | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-forweb2py · web2py · CWE-254 | Kritik9,8 | — | %2,6 | 10 Nis 2017 |
40Planlayın | CVE-2016-0332İstismar yok | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed libm · security identity manager virtual appliance · CWE-254 | Kritik9,8 | — | %2,3 | 12 Oca 2018 |
40Planlayın | CVE-2016-9865İstismar yok | An issue was discovered in phpMyAdmin.phpmyadmin · phpmyadmin · CWE-254 | Kritik9,8 | — | %2,3 | 10 Ara 2016 |
- CVE-2016-229656Planlayın
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows rem
KritikCVSS 9,4SilahlaştırılmışEPSS %64meteocontrol · web\'log basic 10014 May 2016
- CVE-2015-115849Planlayın
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-
KritikCVSS 10,0Kavram kanıtıEPSS %30cups · cups26 Haz 2015
- CVE-2016-016147Planlayın
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege
OrtaCVSS 6,5İstismar yokEPSS %69microsoft · edge12 Nis 2016
- CVE-2015-179345Planlayın
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic
OrtaCVSS 6,5SilahlaştırılmışEPSS %62openssl · openssl9 Tem 2015
- CVE-2016-323843Planlayın
The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201
YüksekCVSS 8,1Kavram kanıtıEPSS %35microsoft · windows 1012 Tem 2016
- CVE-2016-211841Planlayın
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DC
YüksekCVSS 7,5Kavram kanıtıEPSS %37samba · samba12 Nis 2016
- CVE-2016-1017841Planlayın
An issue was discovered on the D-Link DWR-932B router.
KritikCVSS 9,8İstismar yokEPSS %7dlink · dwr-932b firmware30 Oca 2017
- CVE-2016-695741Planlayın
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Contin
KritikCVSS 9,8İstismar yokEPSS %6adobe · acrobat13 Eki 2016
- CVE-2016-421541Planlayın
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Contin
KritikCVSS 9,8İstismar yokEPSS %6adobe · acrobat12 Tem 2016
- CVE-2014-533441Planlayın
FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
KritikCVSS 9,8İstismar yokEPSS %5freenas · freenas8 Oca 2018
- CVE-2015-397241Planlayın
The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easie
KritikCVSS 10,0İstismar yokEPSS %3janitza · umg 50828 Eki 2015
- CVE-2016-578841Planlayın
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it
KritikCVSS 10,0İstismar yokEPSS %2ge · bently nevada 3500\/22m usb firmware24 Kas 2016
- CVE-2015-828640Planlayın
Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP por
KritikCVSS 9,8İstismar yokEPSS %5zhuhai · raysharp firmware18 Şub 2016
- CVE-2015-880340Planlayın
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its
KritikCVSS 9,8İstismar yokEPSS %4nettle project · nettle23 Şub 2016
- CVE-2015-755440Planlayın
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or
KritikCVSS 9,8İstismar yokEPSS %4libtiff · libtiff8 Oca 2016
- CVE-2017-822740Planlayın
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are de
KritikCVSS 9,8İstismar yokEPSS %4amcrest · ipm-721s firmware3 Tem 2019
- CVE-2015-880440Planlayın
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation
KritikCVSS 9,8İstismar yokEPSS %4nettle project · nettle23 Şub 2016
- CVE-2015-885740Planlayın
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which m
KritikCVSS 9,8İstismar yokEPSS %4uglifyjs project · uglifyjs23 Oca 2017
- CVE-2015-647340Planlayın
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
KritikCVSS 9,8İstismar yokEPSS %4wago · 750-849 firmware22 Ağu 2017
- CVE-2016-189640Planlayın
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0
KritikCVSS 9,8İstismar yokEPSS %3lexmark · printer firmware27 Oca 2016
- CVE-2016-662940Planlayın
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive.
KritikCVSS 9,8İstismar yokEPSS %3phpmyadmin · phpmyadmin10 Ara 2016
- CVE-2011-488940Planlayın
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before
KritikCVSS 9,8İstismar yokEPSS %3ibm · websphere application server8 Şub 2018
- CVE-2016-1032140Planlayın
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for
KritikCVSS 9,8İstismar yokEPSS %3web2py · web2py10 Nis 2017
- CVE-2016-033240Planlayın
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed l
KritikCVSS 9,8İstismar yokEPSS %2ibm · security identity manager virtual appliance12 Oca 2018
- CVE-2016-986540Planlayın
An issue was discovered in phpMyAdmin.
KritikCVSS 9,8İstismar yokEPSS %2phpmyadmin · phpmyadmin10 Ara 2016