fedoraproject kayıtları
fedoraproject üreticisine ait 5.450 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 86 · %1,6
- Silahlaştırılmış
- 115 · %2,1
- Pre-auth RCE
- 332
- Düzeltme kaydı olan
- %92,7
- Yayından KEV’e ortanca
- 148 gün
Tekrar eden sınıflar
- CWE-416 Use After Free522
- CWE-787 Out-of-bounds Write376
- CWE-125 Out-of-bounds Read309
- CWE-20 Improper Input Validation224
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer193
- CWE-476 NULL Pointer Dereference187
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5.450 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2021-41773Silahlaştırılmış | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Kritik9,8 | KEV | %100,0 | 5 Eki 2021 |
99Hemen | CVE-2024-4577Silahlaştırılmış | Argument Injection in PHP-CGIphp · php · CWE-78 | Kritik9,8 | KEV | %100,0 | 9 Haz 2024 |
99Hemen | CVE-2021-42013Silahlaştırılmış | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Kritik9,8 | KEV | %100,0 | 7 Eki 2021 |
99Hemen | CVE-2019-11043Silahlaştırılmış | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Kritik9,8 | KEV | %99,8 | 28 Eki 2019 |
99Hemen | CVE-2020-16846Silahlaştırılmış | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Kritik9,8 | KEV | %99,6 | 6 Kas 2020 |
99Hemen | CVE-2020-1938Silahlaştırılmış | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Kritik9,8 | KEV | %99,3 | 24 Şub 2020 |
99Hemen | CVE-2020-7247Silahlaştırılmış | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Kritik9,8 | KEV | %99,0 | 29 Oca 2020 |
98Hemen | CVE-2019-5544Silahlaştırılmış | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Kritik9,8 | KEV | %97,3 | 6 Ara 2019 |
96Hemen | CVE-2021-40438Silahlaştırılmış | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Kritik9,0 | KEV | %100,0 | 16 Eyl 2021 |
96Hemen | CVE-2021-45046Silahlaştırılmış | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Kritik9,0 | KEV | %100,0 | 14 Ara 2021 |
95Hemen | CVE-2023-4863Silahlaştırılmış | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %100,0 | 12 Eyl 2023 |
93Hemen | CVE-2021-39144Silahlaştırılmış | XStream is vulnerable to a Remote Command Execution attackxstream · xstream · CWE-94 | Yüksek8,5 | KEV | %98,1 | 23 Ağu 2021 |
91Hemen | CVE-2021-22204Silahlaştırılmış | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing texiftool project · exiftool · CWE-94 | Yüksek7,8 | KEV | %100,0 | 23 Nis 2021 |
91Hemen | CVE-2021-3156Silahlaştırılmış | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Yüksek7,8 | KEV | %100,0 | 26 Oca 2021 |
90Hemen | CVE-2014-0160Silahlaştırılmış | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Yüksek7,5 | KEV | %100,0 | 7 Nis 2014 |
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
90Hemen | CVE-2019-5418Silahlaştırılmış | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted acceprubyonrails · rails · CWE-22 | Yüksek7,5 | KEV | %98,5 | 27 Mar 2019 |
90Hemen | CVE-2021-21224Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craftgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %84,2 | 26 Nis 2021 |
90Hemen | CVE-2021-44026Silahlaştırılmış | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Kritik9,8 | KEV | %69,9 | 19 Kas 2021 |
89Hemen | CVE-2021-39226Silahlaştırılmış | Snapshot authentication bypass in grafanagrafana · grafana · CWE-287 | Yüksek7,3 | KEV | %99,9 | 5 Eki 2021 |
89Hemen | CVE-2022-0847Silahlaştırılmış | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Yüksek7,8 | KEV | %92,8 | 10 Mar 2022 |
89Hemen | CVE-2020-6418Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | Yüksek8,8 | KEV | %78,8 | 27 Şub 2020 |
86Hemen | CVE-2020-28949Silahlaştırılmış | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | Yüksek7,8 | KEV | %84,6 | 19 Kas 2020 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2021-4177399Hemen
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · http server5 Eki 2021
- CVE-2024-457799Hemen
Argument Injection in PHP-CGI
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php9 Haz 2024
- CVE-2021-4201399Hemen
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · http server7 Eki 2021
- CVE-2019-1104399Hemen
Underflow in PHP-FPM can lead to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php28 Eki 2019
- CVE-2020-1684699Hemen
An issue was discovered in SaltStack Salt through 3002.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100saltstack · salt6 Kas 2020
- CVE-2020-193899Hemen
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · geode24 Şub 2020
- CVE-2020-724799Hemen
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99openbsd · opensmtpd29 Oca 2020
- CVE-2019-554498Hemen
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97openslp · openslp6 Ara 2019
- CVE-2021-4043896Hemen
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100resf · rocky linux16 Eyl 2021
- CVE-2021-4504696Hemen
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100apache · log4j14 Ara 2021
- CVE-2023-486395Hemen
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100google · chrome12 Eyl 2023
- CVE-2021-3914493Hemen
XStream is vulnerable to a Remote Command Execution attack
YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %98xstream · xstream23 Ağu 2021
- CVE-2021-2220491Hemen
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing t
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100exiftool project · exiftool23 Nis 2021
- CVE-2021-315691Hemen
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100sudo project · sudo26 Oca 2021
- CVE-2014-016090Hemen
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100openssl · openssl7 Nis 2014
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2019-541890Hemen
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %99rubyonrails · rails27 Mar 2019
- CVE-2021-2122490Hemen
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %84google · chrome26 Nis 2021
- CVE-2021-4402690Hemen
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %70roundcube · webmail19 Kas 2021
- CVE-2021-3922689Hemen
Snapshot authentication bypass in grafana
YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %100grafana · grafana5 Eki 2021
- CVE-2022-084789Hemen
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93linux · linux kernel10 Mar 2022
- CVE-2020-641889Hemen
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %79google · chrome27 Şub 2020
- CVE-2020-2894986Hemen
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %85php · archive tar19 Kas 2020