CESNET kayıtları
cesnet üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-252 Unchecked Return Value3
- CWE-415 Double Free3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-476 NULL Pointer Dereference3
- CWE-674 Uncontrolled Recursion2
- CWE-121 Stack-based Buffer Overflow2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-19334İstismar yok | In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of tcesnet · libyang · CWE-121 | Kritik9,8 | — | %3,9 | 6 Ara 2019 |
40Planlayın | CVE-2019-19333İstismar yok | In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of tcesnet · libyang · CWE-121 | Kritik9,8 | — | %3,6 | 6 Ara 2019 |
39İzleyin | CVE-2019-15537İstismar yok | The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.cesnet · proxystatistics · CWE-89 | Kritik9,8 | — | %1,6 | 23 Ağu 2019 |
36İzleyin | CVE-2019-20393İstismar yok | A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used.cesnet · libyang · CWE-415 | Yüksek8,8 | — | %2,8 | 22 Oca 2020 |
36İzleyin | CVE-2019-20394İstismar yok | A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement.cesnet · libyang · CWE-415 | Yüksek8,8 | — | %2,8 | 22 Oca 2020 |
36İzleyin | CVE-2019-20397İstismar yok | A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated.cesnet · libyang · CWE-415 | Yüksek8,8 | — | %2,5 | 22 Oca 2020 |
31İzleyin | CVE-2021-28903İstismar yok | A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem().cesnet · libyang · CWE-674 | Yüksek7,5 | — | %2,4 | 20 May 2021 |
30İzleyin | CVE-2021-28906İstismar yok | In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL.cesnet · libyang · CWE-252 | Yüksek7,5 | — | %1,6 | 20 May 2021 |
30İzleyin | CVE-2021-28902İstismar yok | In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL.cesnet · libyang · CWE-252 | Yüksek7,5 | — | %1,6 | 20 May 2021 |
30İzleyin | CVE-2021-28905İstismar yok | In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL.cesnet · libyang · CWE-617 | Yüksek7,5 | — | %1,4 | 20 May 2021 |
30İzleyin | CVE-2021-28904İstismar yok | In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL.cesnet · libyang · CWE-252 | Yüksek7,5 | — | %1,4 | 20 May 2021 |
30İzleyin | CVE-2020-5281İstismar yok | LDAP connector injection in Peruncesnet · perun · CWE-90 | Yüksek7,5 | — | %1,4 | 25 Mar 2020 |
30İzleyin | CVE-2023-26917İstismar yok | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parsecesnet · libyang · CWE-476 | Yüksek7,5 | — | %0,9 | 11 Nis 2023 |
27İzleyin | CVE-2019-20396İstismar yok | A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsincesnet · libyang · CWE-119 | Orta6,5 | — | %1,9 | 22 Oca 2020 |
27İzleyin | CVE-2019-20392İstismar yok | An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is ucesnet · libyang · CWE-119 | Orta6,5 | — | %1,9 | 22 Oca 2020 |
27İzleyin | CVE-2019-20391İstismar yok | An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is ucesnet · libyang · CWE-119 | Orta6,5 | — | %1,9 | 22 Oca 2020 |
27İzleyin | CVE-2019-20395İstismar yok | A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs.cesnet · libyang · CWE-674 | Orta6,5 | — | %1,9 | 22 Oca 2020 |
27İzleyin | CVE-2019-20398İstismar yok | A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy of unresolved ecesnet · libyang · CWE-476 | Orta6,5 | — | %1,8 | 22 Oca 2020 |
22İzleyin | CVE-2016-15014İstismar yok | CESNET theme-cesnet resetpassword.php insufficiently protected credentialscesnet · theme-cesnet · CWE-522 | Orta5,5 | — | %0,2 | 7 Oca 2023 |
21İzleyin | CVE-2023-26916İstismar yok | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.cesnet · libyang · CWE-476 | Orta5,3 | — | %1,0 | 3 Nis 2023 |
- CVE-2019-1933440Planlayın
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of t
KritikCVSS 9,8İstismar yokEPSS %4cesnet · libyang6 Ara 2019
- CVE-2019-1933340Planlayın
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of t
KritikCVSS 9,8İstismar yokEPSS %4cesnet · libyang6 Ara 2019
- CVE-2019-1553739İzleyin
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
KritikCVSS 9,8İstismar yokEPSS %2cesnet · proxystatistics23 Ağu 2019
- CVE-2019-2039336İzleyin
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used.
YüksekCVSS 8,8İstismar yokEPSS %3cesnet · libyang22 Oca 2020
- CVE-2019-2039436İzleyin
A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement.
YüksekCVSS 8,8İstismar yokEPSS %3cesnet · libyang22 Oca 2020
- CVE-2019-2039736İzleyin
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated.
YüksekCVSS 8,8İstismar yokEPSS %3cesnet · libyang22 Oca 2020
- CVE-2021-2890331İzleyin
A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem().
YüksekCVSS 7,5İstismar yokEPSS %2cesnet · libyang20 May 2021
- CVE-2021-2890630İzleyin
In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL.
YüksekCVSS 7,5İstismar yokEPSS %2cesnet · libyang20 May 2021
- CVE-2021-2890230İzleyin
In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL.
YüksekCVSS 7,5İstismar yokEPSS %2cesnet · libyang20 May 2021
- CVE-2021-2890530İzleyin
In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL.
YüksekCVSS 7,5İstismar yokEPSS %1cesnet · libyang20 May 2021
- CVE-2021-2890430İzleyin
In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL.
YüksekCVSS 7,5İstismar yokEPSS %1cesnet · libyang20 May 2021
- CVE-2020-528130İzleyin
LDAP connector injection in Perun
YüksekCVSS 7,5İstismar yokEPSS %1cesnet · perun25 Mar 2020
- CVE-2023-2691730İzleyin
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse
YüksekCVSS 7,5İstismar yokEPSS %1cesnet · libyang11 Nis 2023
- CVE-2019-2039627İzleyin
A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsin
OrtaCVSS 6,5İstismar yokEPSS %2cesnet · libyang22 Oca 2020
- CVE-2019-2039227İzleyin
An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is u
OrtaCVSS 6,5İstismar yokEPSS %2cesnet · libyang22 Oca 2020
- CVE-2019-2039127İzleyin
An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is u
OrtaCVSS 6,5İstismar yokEPSS %2cesnet · libyang22 Oca 2020
- CVE-2019-2039527İzleyin
A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs.
OrtaCVSS 6,5İstismar yokEPSS %2cesnet · libyang22 Oca 2020
- CVE-2019-2039827İzleyin
A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy of unresolved e
OrtaCVSS 6,5İstismar yokEPSS %2cesnet · libyang22 Oca 2020
- CVE-2016-1501422İzleyin
CESNET theme-cesnet resetpassword.php insufficiently protected credentials
OrtaCVSS 5,5İstismar yokEPSS %0cesnet · theme-cesnet7 Oca 2023
- CVE-2023-2691621İzleyin
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.
OrtaCVSS 5,3İstismar yokEPSS %1cesnet · libyang3 Nis 2023