intel kayıtları
intel üreticisine ait 1.868 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %0,2
- Silahlaştırılmış
- 5 · %0,3
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %9,6
- Yayından KEV’e ortanca
- 1118 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation272
- CWE-427 Uncontrolled Search Path Element162
- CWE-284 Improper Access Control106
- CWE-276 Incorrect Default Permissions87
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer71
- CWE-787 Out-of-bounds Write68
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
1.868 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
97Hemen | CVE-2017-5689Silahlaştırılmış | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Kritik9,8 | KEV | %92,2 | 2 May 2017 |
96Hemen | CVE-2021-45046Silahlaştırılmış | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Kritik9,0 | KEV | %100,0 | 14 Ara 2021 |
64Bu hafta | CVE-2015-2291Silahlaştırılmış | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cintel · ethernet diagnostics driver iqvw32.sys · CWE-20 | Yüksek7,8 | KEV | %9,0 | 9 Ağu 2017 |
54Planlayın | CVE-2013-4786Silahlaştırılmış | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtainoracle · fujitsu m10 firmware · CWE-255 | Yüksek7,5 | — | %78,6 | 8 Tem 2013 |
51Planlayın | CVE-2024-22476Kavram kanıtı | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially CWE-20 | Kritik10,0 | — | %36,0 | 16 May 2024 |
50Planlayın | CVE-2017-5753Kavram kanıtı | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an atintel · atom c · CWE-203 | Orta5,6 | — | %93,8 | 4 Oca 2018 |
47Planlayın | CVE-2017-5754Kavram kanıtı | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-200 | Orta5,6 | — | %84,2 | 4 Oca 2018 |
44Planlayın | CVE-2017-5715Kavram kanıtı | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-203 | Orta5,6 | — | %74,0 | 4 Oca 2018 |
42Planlayın | CVE-2000-0384Kavram kanıtı | NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructureintel · netstructure 7110 | Kritik10,0 | — | %5,9 | 8 May 2000 |
41Planlayın | CVE-2009-1385İstismar yok | Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30linux · kernel · CWE-189 | Yüksek7,8 | — | %33,7 | 4 Haz 2009 |
41Planlayın | CVE-2017-12865Kavram kanıtı | Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execintel · connman · CWE-119 | Kritik9,8 | — | %5,5 | 29 Ağu 2017 |
40Planlayın | CVE-2018-3639Kavram kanıtı | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Orta5,5 | — | %60,6 | 22 May 2018 |
40Planlayın | CVE-2020-0594İstismar yok | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an uintel · active management technology firmware · CWE-125 | Kritik9,8 | — | %3,5 | 15 Haz 2020 |
40Planlayın | CVE-2020-0595İstismar yok | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unautintel · active management technology firmware · CWE-416 | Kritik9,8 | — | %3,4 | 15 Haz 2020 |
40Planlayın | CVE-2022-32292İstismar yok | In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow intel · connman · CWE-787 | Kritik9,8 | — | %3,2 | 3 Ağu 2022 |
40Planlayın | CVE-2020-11486İstismar yok | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwarenvidia · dgx-1 · CWE-434 | Kritik9,8 | — | %2,7 | 29 Eki 2020 |
40Planlayın | CVE-2021-33833İstismar yok | ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTintel · connection manager · CWE-787 | Kritik9,8 | — | %2,6 | 9 Haz 2021 |
40Planlayın | CVE-2019-0172İstismar yok | A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privintel · unite | Kritik9,8 | — | %2,3 | 17 May 2019 |
40Planlayın | CVE-2018-12171İstismar yok | Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to intel · bmc firmware | Kritik9,8 | — | %2,1 | 12 Eyl 2018 |
40Planlayın | CVE-2019-11119İstismar yok | Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentialintel · raid web console 3 | Kritik9,8 | — | %2,0 | 13 Haz 2019 |
40Planlayın | CVE-2020-8758İstismar yok | Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, intel · standard manageability | Kritik9,8 | — | %1,9 | 10 Eyl 2020 |
40Planlayın | CVE-2019-0153İstismar yok | Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of pintel · converged security management engine firmware · CWE-119 | Kritik9,8 | — | %1,9 | 17 May 2019 |
40Planlayın | CVE-2019-0101İstismar yok | Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalaintel · unite | Kritik9,8 | — | %1,8 | 18 Şub 2019 |
40Planlayın | CVE-2019-11131İstismar yok | Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentintel · active management technology firmware | Kritik9,8 | — | %1,8 | 18 Ara 2019 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2017-568997Hemen
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92intel · active management technology firmware2 May 2017
- CVE-2021-4504696Hemen
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100apache · log4j14 Ara 2021
- CVE-2015-229164Bu hafta
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to c
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %9intel · ethernet diagnostics driver iqvw32.sys9 Ağu 2017
- CVE-2013-478654Planlayın
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain
YüksekCVSS 7,5SilahlaştırılmışEPSS %79oracle · fujitsu m10 firmware8 Tem 2013
- CVE-2024-2247651Planlayın
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially
KritikCVSS 10,0Kavram kanıtıEPSS %3616 May 2024
- CVE-2017-575350Planlayın
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at
OrtaCVSS 5,6Kavram kanıtıEPSS %94intel · atom c4 Oca 2018
- CVE-2017-575447Planlayın
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
OrtaCVSS 5,6Kavram kanıtıEPSS %84intel · atom c4 Oca 2018
- CVE-2017-571544Planlayın
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
OrtaCVSS 5,6Kavram kanıtıEPSS %74intel · atom c4 Oca 2018
- CVE-2000-038442Planlayın
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure
KritikCVSS 10,0Kavram kanıtıEPSS %6intel · netstructure 71108 May 2000
- CVE-2009-138541Planlayın
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30
YüksekCVSS 7,8İstismar yokEPSS %34linux · kernel4 Haz 2009
- CVE-2017-1286541Planlayın
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or exec
KritikCVSS 9,8Kavram kanıtıEPSS %6intel · connman29 Ağu 2017
- CVE-2018-363940Planlayın
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
OrtaCVSS 5,5Kavram kanıtıEPSS %61intel · atom c22 May 2018
- CVE-2020-059440Planlayın
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an u
KritikCVSS 9,8İstismar yokEPSS %4intel · active management technology firmware15 Haz 2020
- CVE-2020-059540Planlayın
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unaut
KritikCVSS 9,8İstismar yokEPSS %3intel · active management technology firmware15 Haz 2020
- CVE-2022-3229240Planlayın
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow
KritikCVSS 9,8İstismar yokEPSS %3intel · connman3 Ağu 2022
- CVE-2020-1148640Planlayın
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software
KritikCVSS 9,8İstismar yokEPSS %3nvidia · dgx-129 Eki 2020
- CVE-2021-3383340Planlayın
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGT
KritikCVSS 9,8İstismar yokEPSS %3intel · connection manager9 Haz 2021
- CVE-2019-017240Planlayın
A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of priv
KritikCVSS 9,8İstismar yokEPSS %2intel · unite17 May 2019
- CVE-2018-1217140Planlayın
Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to
KritikCVSS 9,8İstismar yokEPSS %2intel · bmc firmware12 Eyl 2018
- CVE-2019-1111940Planlayın
Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potential
KritikCVSS 9,8İstismar yokEPSS %2intel · raid web console 313 Haz 2019
- CVE-2020-875840Planlayın
Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79,
KritikCVSS 9,8İstismar yokEPSS %2intel · standard manageability10 Eyl 2020
- CVE-2019-015340Planlayın
Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of p
KritikCVSS 9,8İstismar yokEPSS %2intel · converged security management engine firmware17 May 2019
- CVE-2019-010140Planlayın
Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escala
KritikCVSS 9,8İstismar yokEPSS %2intel · unite18 Şub 2019
- CVE-2019-1113140Planlayın
Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potent
KritikCVSS 9,8İstismar yokEPSS %2intel · active management technology firmware18 Ara 2019