centos kayıtları
centos üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %12,5
- Silahlaştırılmış
- 1 · %12,5
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- 2532 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-193 Off-by-one Error1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-648 Incorrect Use of Privileged APIs1
- CWE-667 Improper Locking1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2017-1000253Silahlaştırılmış | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86linux · linux kernel · CWE-119 | Yüksek7,8 | KEV | %10,7 | 4 Eki 2017 |
32İzleyin | CVE-2019-19906İstismar yok | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformecyrusimap · cyrus-sasl · CWE-193 | Yüksek7,5 | — | %8,0 | 19 Ara 2019 |
31İzleyin | CVE-2020-5291İstismar yok | Privilege escalation in setuid mode via user namespaces in Bubblewrapprojectatomic · bubblewrap · CWE-648 | Yüksek7,8 | — | %0,9 | 31 Mar 2020 |
30İzleyin | CVE-2022-24121İstismar yok | SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information thrunifiedoffice · total connect now · CWE-89 | Yüksek7,5 | — | %1,3 | 3 Şub 2022 |
27İzleyin | CVE-2011-4144İstismar yok | Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local emc · documentum content server | Orta6,8 | — | %0,3 | 2 Şub 2012 |
26İzleyin | CVE-2022-23238İstismar yok | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less linux · linux kernel | Orta6,5 | — | %0,7 | 10 Ağu 2022 |
24İzleyin | CVE-2021-20315İstismar yok | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" orgnome · gnome-shell · CWE-667 | Orta6,1 | — | %0,2 | 18 Şub 2022 |
19İzleyin | CVE-2007-6283İstismar yok | Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perfofedoraproject · fedora core · CWE-200 | Orta4,9 | — | %0,4 | 17 Ara 2007 |
- CVE-2017-100025364Bu hafta
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %11linux · linux kernel4 Eki 2017
- CVE-2019-1990632İzleyin
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malforme
YüksekCVSS 7,5İstismar yokEPSS %8cyrusimap · cyrus-sasl19 Ara 2019
- CVE-2020-529131İzleyin
Privilege escalation in setuid mode via user namespaces in Bubblewrap
YüksekCVSS 7,8İstismar yokEPSS %1projectatomic · bubblewrap31 Mar 2020
- CVE-2022-2412130İzleyin
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information thr
YüksekCVSS 7,5İstismar yokEPSS %1unifiedoffice · total connect now3 Şub 2022
- CVE-2011-414427İzleyin
Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local
OrtaCVSS 6,8İstismar yokEPSS %0emc · documentum content server2 Şub 2012
- CVE-2022-2323826İzleyin
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less
OrtaCVSS 6,5İstismar yokEPSS %1linux · linux kernel10 Ağu 2022
- CVE-2021-2031524İzleyin
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or
OrtaCVSS 6,1İstismar yokEPSS %0gnome · gnome-shell18 Şub 2022
- CVE-2007-628319İzleyin
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perfo
OrtaCVSS 4,9İstismar yokEPSS %0fedoraproject · fedora core17 Ara 2007