fail2ban kayıtları
fail2ban üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %88,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-287 Improper Authentication1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2021-32749İstismar yok | Possible RCE vulnerability in mailing action using mailutils (mail-whois)fail2ban · fail2ban · CWE-78 | Yüksek8,1 | — | %3,6 | 16 Tem 2021 |
31İzleyin | CVE-2012-5642İstismar yok | server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trifail2ban · fail2ban | Yüksek7,5 | — | %3,1 | 31 Ara 2012 |
29İzleyin | CVE-2007-4321Kavram kanıtı | fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.denyfail2ban · fail2ban | Orta6,8 | — | %5,7 | 13 Ağu 2007 |
21İzleyin | CVE-2013-7176İstismar yok | config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitraryfail2ban · fail2ban · CWE-20 | Orta5,0 | — | %3,2 | 1 Şub 2014 |
21İzleyin | CVE-2013-7177İstismar yok | config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbfail2ban · fail2ban · CWE-20 | Orta5,0 | — | %3,2 | 1 Şub 2014 |
21İzleyin | CVE-2006-6302İstismar yok | fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.defail2ban · fail2ban | Orta5,0 | — | %1,8 | 6 Ara 2006 |
21İzleyin | CVE-2013-2178İstismar yok | The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly vafail2ban · fail2ban · CWE-20 | Orta5,0 | — | %1,8 | 28 Ağu 2013 |
18İzleyin | CVE-2009-5023İstismar yok | The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8fail2ban · fail2ban · CWE-59 | Orta4,7 | — | %0,3 | 10 Haz 2014 |
16İzleyin | CVE-2009-0362İstismar yok | filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forcefail2ban · fail2ban · CWE-287 | Orta4,0 | — | %1,3 | 12 Şub 2009 |
- CVE-2021-3274933İzleyin
Possible RCE vulnerability in mailing action using mailutils (mail-whois)
YüksekCVSS 8,1İstismar yokEPSS %4fail2ban · fail2ban16 Tem 2021
- CVE-2012-564231İzleyin
server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to tri
YüksekCVSS 7,5İstismar yokEPSS %3fail2ban · fail2ban31 Ara 2012
- CVE-2007-432129İzleyin
fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny
OrtaCVSS 6,8Kavram kanıtıEPSS %6fail2ban · fail2ban13 Ağu 2007
- CVE-2013-717621İzleyin
config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary
OrtaCVSS 5,0İstismar yokEPSS %3fail2ban · fail2ban1 Şub 2014
- CVE-2013-717721İzleyin
config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arb
OrtaCVSS 5,0İstismar yokEPSS %3fail2ban · fail2ban1 Şub 2014
- CVE-2006-630221İzleyin
fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.de
OrtaCVSS 5,0İstismar yokEPSS %2fail2ban · fail2ban6 Ara 2006
- CVE-2013-217821İzleyin
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly va
OrtaCVSS 5,0İstismar yokEPSS %2fail2ban · fail2ban28 Ağu 2013
- CVE-2009-502318İzleyin
The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8
OrtaCVSS 4,7İstismar yokEPSS %0fail2ban · fail2ban10 Haz 2014
- CVE-2009-036216İzleyin
filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (force
OrtaCVSS 4,0İstismar yokEPSS %1fail2ban · fail2ban12 Şub 2009