nasa kayıtları
nasa üreticisine ait 62 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 17
- Düzeltme kaydı olan
- %40,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read8
- CWE-122 Heap-based Buffer Overflow6
- CWE-787 Out-of-bounds Write6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-319 Cleartext Transmission of Sensitive Information4
- CWE-502 Deserialization of Untrusted Data4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
62 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-1010060İstismar yok | NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow.nasa · cfitsio · CWE-119 | Kritik9,8 | — | %7,2 | 16 Tem 2019 |
40Planlayın | CVE-2024-55030İstismar yok | A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.nasa · fprime · CWE-77 | Kritik9,8 | — | %1,8 | 25 Mar 2025 |
39İzleyin | CVE-2024-55028İstismar yok | A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a craftednasa · fprime · CWE-94 | Kritik9,8 | — | %0,8 | 25 Mar 2025 |
39İzleyin | CVE-2026-41144İstismar yok | F´ (F Prime) has Integer Overflow in FileUplinknasa · fprime · CWE-190 | Kritik9,8 | — | %0,8 | 21 Nis 2026 |
39İzleyin | CVE-2024-35056İstismar yok | NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.nasa · ait core · CWE-89 | Kritik9,8 | — | %0,6 | 21 May 2024 |
39İzleyin | CVE-2025-46674İstismar yok | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading tnasa · cryptolib · CWE-489 | Kritik9,9 | — | %0,6 | 26 Nis 2025 |
39İzleyin | CVE-2025-25373İstismar yok | The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the nasa · core flight system · CWE-732 | Kritik9,8 | — | %0,5 | 25 Mar 2025 |
39İzleyin | CVE-2025-46673İstismar yok | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Dnasa · cryptolib · CWE-913 | Kritik9,9 | — | %0,5 | 26 Nis 2025 |
37İzleyin | CVE-2025-30216Kavram kanıtı | CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Lengthnasa · cryptolib · CWE-122 | Kritik9,1 | — | %2,7 | 25 Mar 2025 |
37İzleyin | CVE-2026-60113İstismar yok | AIT-DSN < 2.2.2 Missing Authentication via SLE API Routesnasa · ait dsn · CWE-306 | Kritik9,3 | — | %0,8 | 29 Tem 2026 |
37İzleyin | CVE-2026-60112İstismar yok | AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()nasa · ait gui · CWE-306 | Kritik9,3 | — | %0,8 | 29 Tem 2026 |
37İzleyin | CVE-2025-30356İstismar yok | Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`nasa · cryptolib · CWE-191 | Kritik9,3 | — | %0,7 | 1 Nis 2025 |
36İzleyin | CVE-2018-3849İstismar yok | In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwrinasa · cfitsio · CWE-787 | Yüksek8,8 | — | %3,6 | 16 Nis 2018 |
36İzleyin | CVE-2018-3848İstismar yok | In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwrinasa · cfitsio · CWE-787 | Yüksek8,8 | — | %3,5 | 16 Nis 2018 |
36İzleyin | CVE-2018-3846İstismar yok | In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overnasa · cfitsio · CWE-787 | Yüksek8,8 | — | %3,0 | 16 Nis 2018 |
36İzleyin | CVE-2018-3847İstismar yok | Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42.nasa · cfitsio · CWE-787 | Yüksek8,8 | — | %2,8 | 1 Ağu 2018 |
36İzleyin | CVE-2018-1000047İstismar yok | NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code executnasa · kodiak · CWE-502 | Yüksek8,8 | — | %2,0 | 9 Şub 2018 |
36İzleyin | CVE-2018-1000048İstismar yok | NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can renasa · rtretrievalframework · CWE-502 | Yüksek8,8 | — | %2,0 | 9 Şub 2018 |
35İzleyin | CVE-2025-29912İstismar yok | CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecuritynasa · cryptolib · CWE-122 | Yüksek8,9 | — | %1,1 | 17 Mar 2025 |
35İzleyin | CVE-2025-29909İstismar yok | CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerabilitynasa · cryptolib · CWE-191 | Yüksek8,9 | — | %1,1 | 17 Mar 2025 |
35İzleyin | CVE-2025-29911İstismar yok | CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Functionnasa · cryptolib · CWE-122 | Yüksek8,9 | — | %0,7 | 17 Mar 2025 |
35İzleyin | CVE-2025-29913İstismar yok | CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflownasa · cryptolib · CWE-125 | Yüksek8,9 | — | %0,7 | 17 Mar 2025 |
35İzleyin | CVE-2025-46672İstismar yok | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.nasa · cryptolib · CWE-252 | Yüksek8,8 | — | %0,5 | 26 Nis 2025 |
35İzleyin | CVE-2025-64096İstismar yok | CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length checknasa · cryptolib · CWE-121 | Yüksek8,8 | — | %0,5 | 30 Eki 2025 |
34İzleyin | CVE-2025-54878İstismar yok | Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`nasa · cryptolib · CWE-122 | Yüksek8,6 | — | %0,4 | 11 Ağu 2025 |
- CVE-2019-101006041Planlayın
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %7nasa · cfitsio16 Tem 2019
- CVE-2024-5503040Planlayın
A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.
KritikCVSS 9,8İstismar yokEPSS %2nasa · fprime25 Mar 2025
- CVE-2024-5502839İzleyin
A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted
KritikCVSS 9,8İstismar yokEPSS %1nasa · fprime25 Mar 2025
- CVE-2026-4114439İzleyin
F´ (F Prime) has Integer Overflow in FileUplink
KritikCVSS 9,8İstismar yokEPSS %1nasa · fprime21 Nis 2026
- CVE-2024-3505639İzleyin
NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.
KritikCVSS 9,8İstismar yokEPSS %1nasa · ait core21 May 2024
- CVE-2025-4667439İzleyin
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading t
KritikCVSS 9,9İstismar yokEPSS %1nasa · cryptolib26 Nis 2025
- CVE-2025-2537339İzleyin
The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the
KritikCVSS 9,8İstismar yokEPSS %1nasa · core flight system25 Mar 2025
- CVE-2025-4667339İzleyin
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space D
KritikCVSS 9,9İstismar yokEPSS %0nasa · cryptolib26 Nis 2025
- CVE-2025-3021637İzleyin
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
KritikCVSS 9,1Kavram kanıtıEPSS %3nasa · cryptolib25 Mar 2025
- CVE-2026-6011337İzleyin
AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes
KritikCVSS 9,3İstismar yokEPSS %1nasa · ait dsn29 Tem 2026
- CVE-2026-6011237İzleyin
AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()
KritikCVSS 9,3İstismar yokEPSS %1nasa · ait gui29 Tem 2026
- CVE-2025-3035637İzleyin
Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`
KritikCVSS 9,3İstismar yokEPSS %1nasa · cryptolib1 Nis 2025
- CVE-2018-384936İzleyin
In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwri
YüksekCVSS 8,8İstismar yokEPSS %4nasa · cfitsio16 Nis 2018
- CVE-2018-384836İzleyin
In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwri
YüksekCVSS 8,8İstismar yokEPSS %4nasa · cfitsio16 Nis 2018
- CVE-2018-384636İzleyin
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer over
YüksekCVSS 8,8İstismar yokEPSS %3nasa · cfitsio16 Nis 2018
- CVE-2018-384736İzleyin
Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42.
YüksekCVSS 8,8İstismar yokEPSS %3nasa · cfitsio1 Ağu 2018
- CVE-2018-100004736İzleyin
NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execut
YüksekCVSS 8,8İstismar yokEPSS %2nasa · kodiak9 Şub 2018
- CVE-2018-100004836İzleyin
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can re
YüksekCVSS 8,8İstismar yokEPSS %2nasa · rtretrievalframework9 Şub 2018
- CVE-2025-2991235İzleyin
CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity
YüksekCVSS 8,9İstismar yokEPSS %1nasa · cryptolib17 Mar 2025
- CVE-2025-2990935İzleyin
CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability
YüksekCVSS 8,9İstismar yokEPSS %1nasa · cryptolib17 Mar 2025
- CVE-2025-2991135İzleyin
CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function
YüksekCVSS 8,9İstismar yokEPSS %1nasa · cryptolib17 Mar 2025
- CVE-2025-2991335İzleyin
CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow
YüksekCVSS 8,9İstismar yokEPSS %1nasa · cryptolib17 Mar 2025
- CVE-2025-4667235İzleyin
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
YüksekCVSS 8,8İstismar yokEPSS %1nasa · cryptolib26 Nis 2025
- CVE-2025-6409635İzleyin
CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length check
YüksekCVSS 8,8İstismar yokEPSS %1nasa · cryptolib30 Eki 2025
- CVE-2025-5487834İzleyin
Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`
YüksekCVSS 8,6İstismar yokEPSS %0nasa · cryptolib11 Ağu 2025