İçeriğe atla
Noroxi

redislabs kayıtları

redislabs üreticisine ait 26 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %3,8
Pre-auth RCE
3
Düzeltme kaydı olan
%80,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

26 kayıt
  • CVE-2018-11218
    57Planlayın

    Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0

    KritikCVSS 9,8SilahlaştırılmışEPSS %59

    redislabs · redis17 Haz 2018

  • CVE-2016-8339
    43Planlayın

    A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.

    KritikCVSS 9,8İstismar yokEPSS %15

    redislabs · redis28 Eki 2016

  • CVE-2015-4335
    43Planlayın

    Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

    KritikCVSS 10,0İstismar yokEPSS %9

    redislabs · redis9 Haz 2015

  • CVE-2018-11219
    41Planlayın

    An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x befor

    KritikCVSS 9,8İstismar yokEPSS %7

    redislabs · redis17 Haz 2018

  • CVE-2017-15047
    40Planlayın

    The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and appl

    KritikCVSS 9,8İstismar yokEPSS %2

    redislabs · redis6 Eki 2017

  • CVE-2021-32761
    39İzleyin

    Integer overflow issues with *BIT commands on 32-bit systems

    YüksekCVSS 7,5İstismar yokEPSS %31

    redislabs · redis21 Tem 2021

  • CVE-2023-47003
    39İzleyin

    An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBloc

    KritikCVSS 9,8İstismar yokEPSS %1

    redislabs · redisgraph16 Kas 2023

  • CVE-2018-12453
    37İzleyin

    Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-se

    YüksekCVSS 7,5Kavram kanıtıEPSS %24

    redislabs · redis16 Haz 2018

  • CVE-2019-10192
    36İzleyin

    A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x

    YüksekCVSS 7,2İstismar yokEPSS %26

    redislabs · redis11 Tem 2019

  • CVE-2021-21309
    36İzleyin

    Integer overflow on 32-bit systems

    YüksekCVSS 8,8İstismar yokEPSS %5

    redislabs · redis26 Şub 2021

  • CVE-2021-32625
    36İzleyin

    Redis vulnerability in STRALGO LCS on 32-bit systems

    YüksekCVSS 8,8İstismar yokEPSS %4

    redislabs · redis2 Haz 2021

  • CVE-2021-29477
    36İzleyin

    Vulnerability in the STRALGO LCS command

    YüksekCVSS 8,8İstismar yokEPSS %4

    redislabs · redis4 May 2021

  • CVE-2021-29478
    36İzleyin

    Vulnerability in the COPY command for large intsets

    YüksekCVSS 8,8İstismar yokEPSS %4

    redislabs · redis4 May 2021

  • CVE-2019-10193
    35İzleyin

    A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.

    YüksekCVSS 7,2İstismar yokEPSS %24

    redislabs · redis11 Tem 2019

  • CVE-2023-47004
    35İzleyin

    Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code

    YüksekCVSS 8,8İstismar yokEPSS %1

    redislabs · redisgraph6 Kas 2023

  • CVE-2018-12326
    34İzleyin

    Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to high

    YüksekCVSS 8,4Kavram kanıtıEPSS %3

    redislabs · redis17 Haz 2018

  • CVE-2015-8080
    31İzleyin

    Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attacke

    YüksekCVSS 7,5İstismar yokEPSS %5

    redislabs · redis13 Nis 2016

  • CVE-2020-14147
    31İzleyin

    An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run L

    YüksekCVSS 7,7İstismar yokEPSS %3

    redislabs · redis15 Haz 2020

  • CVE-2020-7105
    31İzleyin

    async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

    YüksekCVSS 7,5İstismar yokEPSS %3

    redislabs · hiredis16 Oca 2020

  • CVE-2016-10517
    30İzleyin

    networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not vali

    YüksekCVSS 7,4İstismar yokEPSS %2

    redislabs · redis24 Eki 2017

  • CVE-2020-35668
    30İzleyin

    RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as

    YüksekCVSS 7,5İstismar yokEPSS %2

    redislabs · redisgraph23 Ara 2020

  • CVE-2020-21468
    30İzleyin

    A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).

    YüksekCVSS 7,5İstismar yokEPSS %1

    redislabs · redis20 Eyl 2021

  • CVE-2013-0178
    22İzleyin

    Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

    OrtaCVSS 5,5İstismar yokEPSS %0

    redislabs · redis1 Kas 2019

  • CVE-2013-0180
    22İzleyin

    Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

    OrtaCVSS 5,5İstismar yokEPSS %0

    redislabs · redis1 Kas 2019

  • CVE-2021-3470
    21İzleyin

    A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jem

    OrtaCVSS 5,3İstismar yokEPSS %1

    redislabs · redis31 Mar 2021