redislabs kayıtları
redislabs üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,8
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %80,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-190 Integer Overflow or Wraparound6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-476 NULL Pointer Dereference3
- CWE-787 Out-of-bounds Write3
- CWE-20 Improper Input Validation2
- CWE-121 Stack-based Buffer Overflow1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2018-11218Silahlaştırılmış | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 redislabs · redis · CWE-787 | Kritik9,8 | — | %59,0 | 17 Haz 2018 |
43Planlayın | CVE-2016-8339İstismar yok | A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.redislabs · redis · CWE-787 | Kritik9,8 | — | %14,8 | 28 Eki 2016 |
43Planlayın | CVE-2015-4335İstismar yok | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.redislabs · redis · CWE-17 | Kritik10,0 | — | %9,5 | 9 Haz 2015 |
41Planlayın | CVE-2018-11219İstismar yok | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x beforredislabs · redis · CWE-190 | Kritik9,8 | — | %7,0 | 17 Haz 2018 |
40Planlayın | CVE-2017-15047İstismar yok | The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and applredislabs · redis · CWE-119 | Kritik9,8 | — | %1,8 | 6 Eki 2017 |
39İzleyin | CVE-2021-32761İstismar yok | Integer overflow issues with *BIT commands on 32-bit systemsredislabs · redis · CWE-125 | Yüksek7,5 | — | %31,2 | 21 Tem 2021 |
39İzleyin | CVE-2023-47003İstismar yok | An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlocredislabs · redisgraph · CWE-476 | Kritik9,8 | — | %1,1 | 16 Kas 2023 |
37İzleyin | CVE-2018-12453Kavram kanıtı | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-seredislabs · redis · CWE-704 | Yüksek7,5 | — | %23,9 | 16 Haz 2018 |
36İzleyin | CVE-2019-10192İstismar yok | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.xredislabs · redis · CWE-122 | Yüksek7,2 | — | %26,0 | 11 Tem 2019 |
36İzleyin | CVE-2021-21309İstismar yok | Integer overflow on 32-bit systemsredislabs · redis · CWE-190 | Yüksek8,8 | — | %4,8 | 26 Şub 2021 |
36İzleyin | CVE-2021-32625İstismar yok | Redis vulnerability in STRALGO LCS on 32-bit systemsredislabs · redis · CWE-680 | Yüksek8,8 | — | %4,1 | 2 Haz 2021 |
36İzleyin | CVE-2021-29477İstismar yok | Vulnerability in the STRALGO LCS commandredislabs · redis · CWE-190 | Yüksek8,8 | — | %4,0 | 4 May 2021 |
36İzleyin | CVE-2021-29478İstismar yok | Vulnerability in the COPY command for large intsetsredislabs · redis · CWE-190 | Yüksek8,8 | — | %3,6 | 4 May 2021 |
35İzleyin | CVE-2019-10193İstismar yok | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.redislabs · redis · CWE-121 | Yüksek7,2 | — | %23,7 | 11 Tem 2019 |
35İzleyin | CVE-2023-47004İstismar yok | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code redislabs · redisgraph · CWE-787 | Yüksek8,8 | — | %1,0 | 6 Kas 2023 |
34İzleyin | CVE-2018-12326Kavram kanıtı | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to highredislabs · redis · CWE-119 | Yüksek8,4 | — | %2,7 | 17 Haz 2018 |
31İzleyin | CVE-2015-8080İstismar yok | Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackeredislabs · redis · CWE-190 | Yüksek7,5 | — | %4,6 | 13 Nis 2016 |
31İzleyin | CVE-2020-14147İstismar yok | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lredislabs · redis · CWE-190 | Yüksek7,7 | — | %3,1 | 15 Haz 2020 |
31İzleyin | CVE-2020-7105İstismar yok | async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.redislabs · hiredis · CWE-476 | Yüksek7,5 | — | %2,7 | 16 Oca 2020 |
30İzleyin | CVE-2016-10517İstismar yok | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valiredislabs · redis · CWE-254 | Yüksek7,4 | — | %2,1 | 24 Eki 2017 |
30İzleyin | CVE-2020-35668İstismar yok | RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as redislabs · redisgraph · CWE-476 | Yüksek7,5 | — | %1,6 | 23 Ara 2020 |
30İzleyin | CVE-2020-21468İstismar yok | A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).redislabs · redis | Yüksek7,5 | — | %1,2 | 20 Eyl 2021 |
22İzleyin | CVE-2013-0178İstismar yok | Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.redislabs · redis · CWE-20 | Orta5,5 | — | %0,4 | 1 Kas 2019 |
22İzleyin | CVE-2013-0180İstismar yok | Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.redislabs · redis · CWE-20 | Orta5,5 | — | %0,3 | 1 Kas 2019 |
21İzleyin | CVE-2021-3470İstismar yok | A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemredislabs · redis · CWE-119 | Orta5,3 | — | %1,1 | 31 Mar 2021 |
- CVE-2018-1121857Planlayın
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0
KritikCVSS 9,8SilahlaştırılmışEPSS %59redislabs · redis17 Haz 2018
- CVE-2016-833943Planlayın
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.
KritikCVSS 9,8İstismar yokEPSS %15redislabs · redis28 Eki 2016
- CVE-2015-433543Planlayın
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
KritikCVSS 10,0İstismar yokEPSS %9redislabs · redis9 Haz 2015
- CVE-2018-1121941Planlayın
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x befor
KritikCVSS 9,8İstismar yokEPSS %7redislabs · redis17 Haz 2018
- CVE-2017-1504740Planlayın
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and appl
KritikCVSS 9,8İstismar yokEPSS %2redislabs · redis6 Eki 2017
- CVE-2021-3276139İzleyin
Integer overflow issues with *BIT commands on 32-bit systems
YüksekCVSS 7,5İstismar yokEPSS %31redislabs · redis21 Tem 2021
- CVE-2023-4700339İzleyin
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBloc
KritikCVSS 9,8İstismar yokEPSS %1redislabs · redisgraph16 Kas 2023
- CVE-2018-1245337İzleyin
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-se
YüksekCVSS 7,5Kavram kanıtıEPSS %24redislabs · redis16 Haz 2018
- CVE-2019-1019236İzleyin
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x
YüksekCVSS 7,2İstismar yokEPSS %26redislabs · redis11 Tem 2019
- CVE-2021-2130936İzleyin
Integer overflow on 32-bit systems
YüksekCVSS 8,8İstismar yokEPSS %5redislabs · redis26 Şub 2021
- CVE-2021-3262536İzleyin
Redis vulnerability in STRALGO LCS on 32-bit systems
YüksekCVSS 8,8İstismar yokEPSS %4redislabs · redis2 Haz 2021
- CVE-2021-2947736İzleyin
Vulnerability in the STRALGO LCS command
YüksekCVSS 8,8İstismar yokEPSS %4redislabs · redis4 May 2021
- CVE-2021-2947836İzleyin
Vulnerability in the COPY command for large intsets
YüksekCVSS 8,8İstismar yokEPSS %4redislabs · redis4 May 2021
- CVE-2019-1019335İzleyin
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.
YüksekCVSS 7,2İstismar yokEPSS %24redislabs · redis11 Tem 2019
- CVE-2023-4700435İzleyin
Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code
YüksekCVSS 8,8İstismar yokEPSS %1redislabs · redisgraph6 Kas 2023
- CVE-2018-1232634İzleyin
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to high
YüksekCVSS 8,4Kavram kanıtıEPSS %3redislabs · redis17 Haz 2018
- CVE-2015-808031İzleyin
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attacke
YüksekCVSS 7,5İstismar yokEPSS %5redislabs · redis13 Nis 2016
- CVE-2020-1414731İzleyin
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run L
YüksekCVSS 7,7İstismar yokEPSS %3redislabs · redis15 Haz 2020
- CVE-2020-710531İzleyin
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
YüksekCVSS 7,5İstismar yokEPSS %3redislabs · hiredis16 Oca 2020
- CVE-2016-1051730İzleyin
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not vali
YüksekCVSS 7,4İstismar yokEPSS %2redislabs · redis24 Eki 2017
- CVE-2020-3566830İzleyin
RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as
YüksekCVSS 7,5İstismar yokEPSS %2redislabs · redisgraph23 Ara 2020
- CVE-2020-2146830İzleyin
A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).
YüksekCVSS 7,5İstismar yokEPSS %1redislabs · redis20 Eyl 2021
- CVE-2013-017822İzleyin
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
OrtaCVSS 5,5İstismar yokEPSS %0redislabs · redis1 Kas 2019
- CVE-2013-018022İzleyin
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
OrtaCVSS 5,5İstismar yokEPSS %0redislabs · redis1 Kas 2019
- CVE-2021-347021İzleyin
A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jem
OrtaCVSS 5,3İstismar yokEPSS %1redislabs · redis31 Mar 2021