openslp kayıtları
openslp üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %11,1
- Silahlaştırılmış
- 1 · %11,1
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- 698 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-415 Double Free1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2019-5544Silahlaştırılmış | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Kritik9,8 | KEV | %97,3 | 6 Ara 2019 |
43Planlayın | CVE-2016-7567Kavram kanıtı | Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact openslp · openslp · CWE-119 | Kritik9,8 | — | %12,5 | 23 Oca 2017 |
40Planlayın | CVE-2017-17833İstismar yok | OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-seopenslp · openslp · CWE-119 | Kritik9,8 | — | %3,8 | 23 Nis 2018 |
33İzleyin | CVE-2012-4428İstismar yok | openslp: SLPIntersectStringList()' Function has a DoS vulnerabilityopenslp · openslp · CWE-125 | Yüksek7,5 | — | %9,6 | 2 Ara 2019 |
32İzleyin | CVE-2015-5177İstismar yok | Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial oopenslp · openslp · CWE-415 | Yüksek7,5 | — | %6,3 | 22 Eki 2017 |
32İzleyin | CVE-2016-4912İstismar yok | The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference andopenslp · openslp · CWE-476 | Yüksek7,5 | — | %5,4 | 27 Mar 2017 |
31İzleyin | CVE-2005-0769İstismar yok | Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.openslp · openslp | Yüksek7,5 | — | %2,6 | 2 May 2005 |
25İzleyin | CVE-2010-3609Kavram kanıtı | The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol openslp · openslp | Orta5,0 | — | %17,2 | 11 Mar 2011 |
8İzleyin | CVE-2003-0875İstismar yok | Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via topenslp · openslp | Düşük2,1 | — | %0,3 | 17 Kas 2003 |
- CVE-2019-554498Hemen
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97openslp · openslp6 Ara 2019
- CVE-2016-756743Planlayın
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact
KritikCVSS 9,8Kavram kanıtıEPSS %12openslp · openslp23 Oca 2017
- CVE-2017-1783340Planlayın
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-se
KritikCVSS 9,8İstismar yokEPSS %4openslp · openslp23 Nis 2018
- CVE-2012-442833İzleyin
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
YüksekCVSS 7,5İstismar yokEPSS %10openslp · openslp2 Ara 2019
- CVE-2015-517732İzleyin
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial o
YüksekCVSS 7,5İstismar yokEPSS %6openslp · openslp22 Eki 2017
- CVE-2016-491232İzleyin
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and
YüksekCVSS 7,5İstismar yokEPSS %5openslp · openslp27 Mar 2017
- CVE-2005-076931İzleyin
Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.
YüksekCVSS 7,5İstismar yokEPSS %3openslp · openslp2 May 2005
- CVE-2010-360925İzleyin
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol
OrtaCVSS 5,0Kavram kanıtıEPSS %17openslp · openslp11 Mar 2011
- CVE-2003-08758İzleyin
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via t
DüşükCVSS 2,1İstismar yokEPSS %0openslp · openslp17 Kas 2003