İçeriğe atla
Noroxi

canonical kayıtları

canonical üreticisine ait 4.318 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
47 · %1,1
Silahlaştırılmış
100 · %2,3
Pre-auth RCE
493
Düzeltme kaydı olan
%88,7
Yayından KEV’e ortanca
1939 gün

Tüm kayıtlar

4.318 kayıt
  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99

    redis · redis18 Şub 2022

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    exim · exim5 Haz 2019

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • Underflow in PHP-FPM can lead to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php28 Eki 2019

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    openbsd · opensmtpd29 Oca 2020

  • Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    oracle · jdk10 Oca 2013

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    oracle · jdk19 Eki 2011

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    saltstack · salt30 Nis 2020

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96

    oracle · jre1 Nis 2010

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    oracle · jdk21 Nis 2016

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90

    apache · tomcat6 Nis 2017

  • An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %82

    exim · exim8 Şub 2018

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100

    apache · tomcat3 Eki 2017

  • The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor

    YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %97

    imagemagick · imagemagick5 May 2016

  • Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %72

    exim · exim14 Ara 2010

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    openssl · openssl7 Nis 2014

  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %94

    polkit project · polkit28 Oca 2022

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69

    mozilla · firefox25 Haz 2013

  • The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69

    mozilla · firefox7 Ağu 2015

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81

    gnu · glibc3 Eki 2023

  • Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha

    YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %84

    linux · linux kernel10 Kas 2016

  • A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %72

    google · android11 Eki 2019

  • Netlogon Elevation of Privilege Vulnerability

    OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %99

    microsoft · windows server 190317 Ağu 2020

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %86

    saltstack · salt30 Nis 2020