İçeriğe atla
Noroxi

OSSEC kayıtları

ossec üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

12 kayıt
  • CVE-2020-8443
    40Planlayın

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas

    KritikCVSS 9,8İstismar yokEPSS %3

    ossec · ossec29 Oca 2020

  • CVE-2020-8444
    40Planlayın

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin

    KritikCVSS 9,8İstismar yokEPSS %2

    ossec · ossec29 Oca 2020

  • CVE-2020-8445
    40Planlayın

    In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newline

    KritikCVSS 9,8İstismar yokEPSS %2

    ossec · ossec29 Oca 2020

  • CVE-2020-8447
    40Planlayın

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin

    KritikCVSS 9,8İstismar yokEPSS %2

    ossec · ossec29 Oca 2020

  • CVE-2020-8442
    36İzleyin

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ov

    YüksekCVSS 8,8İstismar yokEPSS %2

    ossec · ossec29 Oca 2020

  • CVE-2018-19666
    31İzleyin

    The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full

    YüksekCVSS 7,8İstismar yokEPSS %1

    ossec · ossec29 Kas 2018

  • CVE-2021-28040
    30İzleyin

    An issue was discovered in OSSEC 3.6.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    ossec · ossec5 Mar 2021

  • CVE-2014-5284
    29İzleyin

    host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local user

    YüksekCVSS 7,2Kavram kanıtıEPSS %2

    ossec · ossec1 Ara 2014

  • CVE-2015-3222
    29İzleyin

    syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

    YüksekCVSS 7,0Kavram kanıtıEPSS %2

    ossec · ossec7 Eyl 2017

  • CVE-2016-4847
    24İzleyin

    Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scrip

    OrtaCVSS 6,1İstismar yokEPSS %1

    ossec · web ui20 Nis 2017

  • CVE-2020-8446
    22İzleyin

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with w

    OrtaCVSS 5,5İstismar yokEPSS %1

    ossec · ossec29 Oca 2020

  • CVE-2020-8448
    22İzleyin

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (N

    OrtaCVSS 5,5İstismar yokEPSS %0

    ossec · ossec29 Oca 2020