OSSEC kayıtları
ossec üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-416 Use After Free2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-674 Uncontrolled Recursion1
- CWE-787 Out-of-bounds Write1
- CWE-193 Off-by-one Error1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-8443İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-basossec · ossec · CWE-193 | Kritik9,8 | — | %2,7 | 29 Oca 2020 |
40Planlayın | CVE-2020-8444İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durinossec · ossec · CWE-416 | Kritik9,8 | — | %2,5 | 29 Oca 2020 |
40Planlayın | CVE-2020-8445İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlineossec · ossec · CWE-20 | Kritik9,8 | — | %2,3 | 29 Oca 2020 |
40Planlayın | CVE-2020-8447İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durinossec · ossec · CWE-416 | Kritik9,8 | — | %1,9 | 29 Oca 2020 |
36İzleyin | CVE-2020-8442İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ovossec · ossec · CWE-787 | Yüksek8,8 | — | %2,4 | 29 Oca 2020 |
31İzleyin | CVE-2018-19666İstismar yok | The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging fullossec · ossec · CWE-22 | Yüksek7,8 | — | %0,8 | 29 Kas 2018 |
30İzleyin | CVE-2021-28040İstismar yok | An issue was discovered in OSSEC 3.6.0.ossec · ossec · CWE-674 | Yüksek7,5 | — | %1,2 | 5 Mar 2021 |
29İzleyin | CVE-2014-5284Kavram kanıtı | host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local userossec · ossec · CWE-264 | Yüksek7,2 | — | %2,4 | 1 Ara 2014 |
29İzleyin | CVE-2015-3222Kavram kanıtı | syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.ossec · ossec · CWE-264 | Yüksek7,0 | — | %2,0 | 7 Eyl 2017 |
24İzleyin | CVE-2016-4847İstismar yok | Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scripossec · web ui · CWE-79 | Orta6,1 | — | %1,3 | 20 Nis 2017 |
22İzleyin | CVE-2020-8446İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with wossec · ossec · CWE-22 | Orta5,5 | — | %0,5 | 29 Oca 2020 |
22İzleyin | CVE-2020-8448İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (Nossec · ossec · CWE-476 | Orta5,5 | — | %0,5 | 29 Oca 2020 |
- CVE-2020-844340Planlayın
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas
KritikCVSS 9,8İstismar yokEPSS %3ossec · ossec29 Oca 2020
- CVE-2020-844440Planlayın
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin
KritikCVSS 9,8İstismar yokEPSS %2ossec · ossec29 Oca 2020
- CVE-2020-844540Planlayın
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newline
KritikCVSS 9,8İstismar yokEPSS %2ossec · ossec29 Oca 2020
- CVE-2020-844740Planlayın
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free durin
KritikCVSS 9,8İstismar yokEPSS %2ossec · ossec29 Oca 2020
- CVE-2020-844236İzleyin
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer ov
YüksekCVSS 8,8İstismar yokEPSS %2ossec · ossec29 Oca 2020
- CVE-2018-1966631İzleyin
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full
YüksekCVSS 7,8İstismar yokEPSS %1ossec · ossec29 Kas 2018
- CVE-2021-2804030İzleyin
An issue was discovered in OSSEC 3.6.0.
YüksekCVSS 7,5İstismar yokEPSS %1ossec · ossec5 Mar 2021
- CVE-2014-528429İzleyin
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local user
YüksekCVSS 7,2Kavram kanıtıEPSS %2ossec · ossec1 Ara 2014
- CVE-2015-322229İzleyin
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
YüksekCVSS 7,0Kavram kanıtıEPSS %2ossec · ossec7 Eyl 2017
- CVE-2016-484724İzleyin
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web scrip
OrtaCVSS 6,1İstismar yokEPSS %1ossec · web ui20 Nis 2017
- CVE-2020-844622İzleyin
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with w
OrtaCVSS 5,5İstismar yokEPSS %1ossec · ossec29 Oca 2020
- CVE-2020-844822İzleyin
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (N
OrtaCVSS 5,5İstismar yokEPSS %0ossec · ossec29 Oca 2020