İçeriğe atla
Noroxi

NSA kayıtları

nsa üreticisine ait 37 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%29,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

37 kayıt
  • CVE-2019-16941
    41Planlayın

    NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    nsa · ghidra28 Eyl 2019

  • CVE-2023-22671
    40Planlayın

    Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injectio

    KritikCVSS 9,8İstismar yokEPSS %3

    nsa · ghidra6 Oca 2023

  • CVE-2021-32639
    39İzleyin

    Server-Side Request Forgery (SSRF) in emissary:emissary

    KritikCVSS 9,9İstismar yokEPSS %1

    nsa · emissary2 Tem 2021

  • CVE-2021-32647
    37İzleyin

    Post-authentication Remote Code Execution (RCE) in emissary:emissary

    KritikCVSS 9,1İstismar yokEPSS %3

    nsa · emissary1 Haz 2021

  • CVE-2019-13625
    37İzleyin

    NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.

    KritikCVSS 9,1İstismar yokEPSS %2

    nsa · ghidra16 Tem 2019

  • CVE-2026-35580
    36İzleyin

    Emissary has GitHub Actions Shell Injection via Workflow Inputs

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    nsa · emissary7 Nis 2026

  • CVE-2021-32094
    35İzleyin

    U.S.

    YüksekCVSS 8,8İstismar yokEPSS %1

    nsa · emissary7 May 2021

  • CVE-2026-35582
    35İzleyin

    Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix

    YüksekCVSS 8,8İstismar yokEPSS %1

    nsa · emissary17 Nis 2026

  • CVE-2026-4946
    35İzleyin

    NSA Ghidra Auto-Analysis Annotation Command Execution

    YüksekCVSS 8,8İstismar yokEPSS %1

    nsa · ghidra29 Mar 2026

  • CVE-2021-32096
    35İzleyin

    The ConsoleAction component of U.S.

    YüksekCVSS 8,8İstismar yokEPSS %1

    nsa · emissary7 May 2021

  • CVE-2026-52751
    34İzleyin

    Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection

    YüksekCVSS 8,6İstismar yokEPSS %1

    nsa · ghidra10 Haz 2026

  • CVE-2026-52758
    34İzleyin

    Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search

    YüksekCVSS 8,7İstismar yokEPSS %1

    nsa · ghidra10 Haz 2026

  • CVE-2026-49498
    34İzleyin

    Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username

    YüksekCVSS 8,7İstismar yokEPSS %0

    nsa · ghidra10 Haz 2026

  • CVE-2026-52754
    34İzleyin

    Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule

    YüksekCVSS 8,7İstismar yokEPSS %0

    nsa · ghidra10 Haz 2026

  • CVE-2026-52750
    33İzleyin

    Ghidra < 12.1- Command Injection via URL Annotation Click

    YüksekCVSS 8,4İstismar yokEPSS %1

    nsa · ghidra10 Haz 2026

  • CVE-2026-52755
    33İzleyin

    Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import

    YüksekCVSS 8,4İstismar yokEPSS %0

    nsa · ghidra10 Haz 2026

  • CVE-2026-52752
    33İzleyin

    Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names

    YüksekCVSS 8,4İstismar yokEPSS %0

    nsa · ghidra10 Haz 2026

  • CVE-2019-13623
    32İzleyin

    In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with

    YüksekCVSS 7,8Kavram kanıtıEPSS %5

    nsa · ghidra16 Tem 2019

  • CVE-2021-32095
    32İzleyin

    U.S.

    YüksekCVSS 8,1İstismar yokEPSS %1

    nsa · emissary7 May 2021

  • CVE-2019-17665
    31İzleyin

    NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.

    YüksekCVSS 7,8İstismar yokEPSS %0

    nsa · ghidra16 Eki 2019

  • CVE-2019-17664
    31İzleyin

    NSA Ghidra through 9.0.4 uses a potentially untrusted search path.

    YüksekCVSS 7,8İstismar yokEPSS %0

    nsa · ghidra16 Eki 2019

  • CVE-2021-32634
    28İzleyin

    Deserialization of Untrusted Data in Emissary

    YüksekCVSS 7,2İstismar yokEPSS %1

    nsa · emissary21 May 2021

  • CVE-2026-35581
    28İzleyin

    Emissary has a Command Injection via PLACE_NAME Configuration in Executrix

    YüksekCVSS 7,2İstismar yokEPSS %1

    nsa · emissary7 Nis 2026

  • CVE-2026-49496
    27İzleyin

    Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocation

    OrtaCVSS 6,9İstismar yokEPSS %0

    nsa · ghidra10 Haz 2026

  • CVE-2021-32093
    26İzleyin

    The ConfigFileAction component of U.S.

    OrtaCVSS 6,5İstismar yokEPSS %1

    nsa · emissary7 May 2021