İçeriğe atla
Noroxi

OneIdentity kayıtları

oneidentity üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%53,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2023-48654
    39İzleyin

    One Identity Password Manager before 5.13.1 allows Kiosk Escape.

    KritikCVSS 9,8İstismar yokEPSS %1

    oneidentity · password manager25 Ara 2023

  • CVE-2008-5110
    38İzleyin

    syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail.

    KritikCVSS 9,3İstismar yokEPSS %2

    oneidentity · syslog-ng17 Kas 2008

  • CVE-2023-51772
    35İzleyin

    One Identity Password Manager before 5.13.1 allows Kiosk Escape.

    YüksekCVSS 8,8İstismar yokEPSS %1

    oneidentity · password manager25 Ara 2023

  • CVE-2002-1200
    32İzleyin

    Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of

    YüksekCVSS 7,5İstismar yokEPSS %6

    oneidentity · syslog-ng28 Eki 2002

  • CVE-2019-13496
    32İzleyin

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defend

    YüksekCVSS 8,1Kavram kanıtıEPSS %1

    oneidentity · cloud access manager4 Kas 2019

  • CVE-2022-38725
    31İzleyin

    An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service vi

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    oneidentity · syslog-ng23 Oca 2023

  • CVE-2020-8019
    31İzleyin

    syslog-ng: Local privilege escalation from new to root in %post

    YüksekCVSS 7,8İstismar yokEPSS %1

    suse · linux enterprise debuginfo29 Haz 2020

  • CVE-2024-47619
    30İzleyin

    tranport: TLS host name wildcard matching too lax

    YüksekCVSS 7,5İstismar yokEPSS %0

    oneidentity · syslog-ng7 May 2025

  • CVE-2019-13498
    29İzleyin

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks

    YüksekCVSS 7,4Kavram kanıtıEPSS %1

    oneidentity · cloud access manager29 Tem 2019

  • CVE-2023-4003
    27İzleyin

    One Identity Password Manager version 5.9.7.1 - Unauthenticated physical access privilege escalation

    OrtaCVSS 6,8İstismar yokEPSS %1

    oneidentity · password manager27 Eyl 2023

  • CVE-2011-0343
    27İzleyin

    Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes s

    OrtaCVSS 6,9İstismar yokEPSS %0

    freebsd · freebsd28 Oca 2011

  • CVE-2019-13497
    26İzleyin

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

    OrtaCVSS 6,5Kavram kanıtıEPSS %1

    oneidentity · cloud access manager4 Kas 2019

  • CVE-2020-7962
    21İzleyin

    An issue was discovered in One Identity Password Manager 5.8.

    OrtaCVSS 5,3İstismar yokEPSS %1

    oneidentity · password manager13 Kas 2020

  • CVE-2024-40595
    21İzleyin

    An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS

    OrtaCVSS 5,3İstismar yokEPSS %0

    24 Eki 2024

  • CVE-2011-1951
    18İzleyin

    lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows

    OrtaCVSS 4,3İstismar yokEPSS %2

    pcre · pcre11 Tem 2011