redhat kayıtları
redhat üreticisine ait 6.164 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 97 · %1,6
- Silahlaştırılmış
- 150 · %2,4
- Pre-auth RCE
- 572
- Düzeltme kaydı olan
- %82,4
- Yayından KEV’e ortanca
- 2108 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation368
- CWE-416 Use After Free295
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer286
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor286
- CWE-125 Out-of-bounds Read239
- CWE-787 Out-of-bounds Write220
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6.164 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2013-2251Silahlaştırılmış | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Kritik9,8 | KEV | %100,0 | 19 Tem 2013 |
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2015-3113Silahlaştırılmış | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Kritik9,8 | KEV | %99,9 | 23 Haz 2015 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
99Hemen | CVE-2015-1427Silahlaştırılmış | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection meelastic · elasticsearch | Kritik9,8 | KEV | %99,9 | 17 Şub 2015 |
99Hemen | CVE-2014-0497Silahlaştırılmış | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Kritik9,8 | KEV | %99,9 | 5 Şub 2014 |
99Hemen | CVE-2019-11043Silahlaştırılmış | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Kritik9,8 | KEV | %99,8 | 28 Eki 2019 |
99Hemen | CVE-2015-5119Silahlaştırılmış | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Kritik9,8 | KEV | %99,3 | 8 Tem 2015 |
99Hemen | CVE-2012-4681Silahlaştırılmış | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Kritik9,8 | KEV | %98,5 | 27 Ağu 2012 |
99Hemen | CVE-2019-7609Silahlaştırılmış | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Kritik10,0 | KEV | %95,3 | 25 Mar 2019 |
98Hemen | CVE-2018-1000861Silahlaştırılmış | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/corjenkins · jenkins · CWE-502 | Kritik9,8 | KEV | %98,3 | 10 Ara 2018 |
98Hemen | CVE-2019-5544Silahlaştırılmış | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Kritik9,8 | KEV | %97,3 | 6 Ara 2019 |
98Hemen | CVE-2019-1003030Silahlaştırılmış | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wojenkins · pipeline\ · CWE-693 | Kritik9,9 | KEV | %96,9 | 8 Mar 2019 |
98Hemen | CVE-2011-3544Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Kritik9,8 | KEV | %96,7 | 19 Eki 2011 |
97Hemen | CVE-2016-4117Silahlaştırılmış | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Kritik9,8 | KEV | %94,4 | 10 May 2016 |
97Hemen | CVE-2015-5122Silahlaştırılmış | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Kritik9,8 | KEV | %94,0 | 14 Tem 2015 |
97Hemen | CVE-2012-1723Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,oracle · jdk · CWE-284 | Kritik9,8 | KEV | %93,7 | 16 Haz 2012 |
97Hemen | CVE-2016-4437Silahlaştırılmış | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Kritik9,8 | KEV | %93,0 | 7 Haz 2016 |
97Hemen | CVE-2016-3427Silahlaştırılmış | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Kritik9,8 | KEV | %92,3 | 21 Nis 2016 |
96Hemen | CVE-2021-40438Silahlaştırılmış | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Kritik9,0 | KEV | %100,0 | 16 Eyl 2021 |
96Hemen | CVE-2017-12149Silahlaştırılmış | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnredhat · jboss enterprise application platform · CWE-502 | Kritik9,8 | KEV | %90,7 | 4 Eki 2017 |
96Hemen | CVE-2016-8735Silahlaştırılmış | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Kritik9,8 | KEV | %90,3 | 6 Nis 2017 |
92Hemen | CVE-2017-12617Silahlaştırılmış | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Yüksek8,1 | KEV | %100,0 | 3 Eki 2017 |
92Hemen | CVE-2017-12615Silahlaştırılmış | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Yüksek8,1 | KEV | %99,6 | 19 Eyl 2017 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2013-225199Hemen
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · archiva19 Tem 2013
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2015-311399Hemen
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player23 Haz 2015
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2015-142799Hemen
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100elastic · elasticsearch17 Şub 2015
- CVE-2014-049799Hemen
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player5 Şub 2014
- CVE-2019-1104399Hemen
Underflow in PHP-FPM can lead to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php28 Eki 2019
- CVE-2015-511999Hemen
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99adobe · flash player8 Tem 2015
- CVE-2012-468199Hemen
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99oracle · jdk27 Ağu 2012
- CVE-2019-760999Hemen
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %95elastic · kibana25 Mar 2019
- CVE-2018-100086198Hemen
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98jenkins · jenkins10 Ara 2018
- CVE-2019-554498Hemen
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97openslp · openslp6 Ara 2019
- CVE-2019-100303098Hemen
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %97jenkins · pipeline\8 Mar 2019
- CVE-2011-354498Hemen
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97oracle · jdk19 Eki 2011
- CVE-2016-411797Hemen
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · flash player10 May 2016
- CVE-2015-512297Hemen
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · flash player14 Tem 2015
- CVE-2012-172397Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94oracle · jdk16 Haz 2012
- CVE-2016-443797Hemen
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93apache · aurora7 Haz 2016
- CVE-2016-342797Hemen
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92oracle · jdk21 Nis 2016
- CVE-2021-4043896Hemen
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100resf · rocky linux16 Eyl 2021
- CVE-2017-1214996Hemen
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %91redhat · jboss enterprise application platform4 Eki 2017
- CVE-2016-873596Hemen
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90apache · tomcat6 Nis 2017
- CVE-2017-1261792Hemen
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100apache · tomcat3 Eki 2017
- CVE-2017-1261592Hemen
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100apache · tomcat19 Eyl 2017