starwindsoftware kayıtları
starwindsoftware üreticisine ait 30 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %3,3
- Silahlaştırılmış
- 1 · %3,3
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %80
- Yayından KEV’e ortanca
- 150 gün
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write5
- CWE-287 Improper Authentication3
- CWE-125 Out-of-bounds Read3
- CWE-416 Use After Free2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-400 Uncontrolled Resource Consumption2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
30 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
89Hemen | CVE-2021-4034Silahlaştırılmış | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Yüksek7,8 | KEV | %94,3 | 28 Oca 2022 |
44Planlayın | CVE-2021-43527İstismar yok | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-mozilla · nss · CWE-787 | Kritik9,8 | — | %17,6 | 8 Ara 2021 |
39İzleyin | CVE-2022-24552İstismar yok | A flaw was found in the REST API in StarWind Stack.starwindsoftware · nas · CWE-78 | Kritik9,8 | — | %1,3 | 6 Şub 2022 |
39İzleyin | CVE-2013-20004İstismar yok | A flaw was found in StarWind iSCSI target.starwindsoftware · iscsi san · CWE-400 | Kritik9,8 | — | %1,2 | 6 Şub 2022 |
37İzleyin | CVE-2021-42574Kavram kanıtı | An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.unicode · unicode · CWE-94 | Yüksek8,3 | — | %12,9 | 1 Kas 2021 |
36İzleyin | CVE-2018-3839İstismar yok | An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.libsdl · sdl image · CWE-787 | Yüksek8,8 | — | %2,6 | 10 Nis 2018 |
36İzleyin | CVE-2022-32268İstismar yok | StarWind SAN and NAS v0.2 build 1914 allow remote code execution.starwindsoftware · starwind san \& nas | Yüksek8,8 | — | %2,3 | 3 Haz 2022 |
35İzleyin | CVE-2022-23858İstismar yok | A flaw was found in the REST API.starwindsoftware · command center | Yüksek8,8 | — | %1,1 | 23 Oca 2022 |
35İzleyin | CVE-2022-24551İstismar yok | A flaw was found in StarWind Stack.starwindsoftware · nas · CWE-287 | Yüksek8,8 | — | %0,9 | 6 Şub 2022 |
31İzleyin | CVE-2020-36385İstismar yok | An issue was discovered in the Linux kernel before 5.10.linux · linux kernel · CWE-416 | Yüksek7,8 | — | %1,5 | 7 Haz 2021 |
31İzleyin | CVE-2020-14409İstismar yok | SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDlibsdl · simple directmedia layer · CWE-190 | Yüksek7,8 | — | %1,3 | 19 Oca 2021 |
30İzleyin | CVE-2007-20001İstismar yok | A flaw was found in StarWind iSCSI target.starwindsoftware · iscsi san · CWE-400 | Yüksek7,5 | — | %1,1 | 6 Şub 2022 |
29İzleyin | CVE-2020-25643İstismar yok | A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.linux · linux kernel · CWE-20 | Yüksek7,2 | — | %3,3 | 6 Eki 2020 |
29İzleyin | CVE-2021-41617Kavram kanıtı | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplementopenbsd · openssh | Yüksek7,0 | — | %2,5 | 26 Eyl 2021 |
28İzleyin | CVE-2021-20271İstismar yok | A flaw was found in RPM's signature check functionality when reading a package file.rpm · rpm · CWE-345 | Yüksek7,0 | — | %0,8 | 26 Mar 2021 |
28İzleyin | CVE-2020-24394İstismar yok | In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesyslinux · linux kernel · CWE-732 | Yüksek7,1 | — | %0,4 | 19 Ağu 2020 |
27İzleyin | CVE-2018-18584İstismar yok | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quacabextract project · cabextract · CWE-787 | Orta6,5 | — | %3,1 | 22 Eki 2018 |
27İzleyin | CVE-2021-37750İstismar yok | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/mit · kerberos 5 · CWE-476 | Orta6,5 | — | %2,2 | 23 Ağu 2021 |
26İzleyin | CVE-2021-42739İstismar yok | The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and driverslinux · linux kernel · CWE-787 | Orta6,7 | — | %0,5 | 20 Eki 2021 |
23İzleyin | CVE-2018-16758İstismar yok | Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the tinc-vpn · tinc · CWE-306 | Orta5,9 | — | %0,9 | 10 Eki 2018 |
22İzleyin | CVE-2018-3837İstismar yok | An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2libsdl · sdl image · CWE-125 | Orta5,5 | — | %1,2 | 10 Nis 2018 |
22İzleyin | CVE-2020-0427İstismar yok | In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.google · android · CWE-125 | Orta5,5 | — | %0,5 | 17 Eyl 2020 |
22İzleyin | CVE-2020-36322İstismar yok | An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.linux · linux kernel · CWE-459 | Orta5,5 | — | %0,4 | 14 Nis 2021 |
22İzleyin | CVE-2020-14314İstismar yok | A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direclinux · linux kernel · CWE-125 | Orta5,5 | — | %0,4 | 15 Eyl 2020 |
22İzleyin | CVE-2020-25704İstismar yok | A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.linux · linux kernel · CWE-401 | Orta5,5 | — | %0,4 | 1 Ara 2020 |
- CVE-2021-403489Hemen
A local privilege escalation vulnerability was found on polkit's pkexec utility.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %94polkit project · polkit28 Oca 2022
- CVE-2021-4352744Planlayın
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-
KritikCVSS 9,8İstismar yokEPSS %18mozilla · nss8 Ara 2021
- CVE-2022-2455239İzleyin
A flaw was found in the REST API in StarWind Stack.
KritikCVSS 9,8İstismar yokEPSS %1starwindsoftware · nas6 Şub 2022
- CVE-2013-2000439İzleyin
A flaw was found in StarWind iSCSI target.
KritikCVSS 9,8İstismar yokEPSS %1starwindsoftware · iscsi san6 Şub 2022
- CVE-2021-4257437İzleyin
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0.
YüksekCVSS 8,3Kavram kanıtıEPSS %13unicode · unicode1 Kas 2021
- CVE-2018-383936İzleyin
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2.
YüksekCVSS 8,8İstismar yokEPSS %3libsdl · sdl image10 Nis 2018
- CVE-2022-3226836İzleyin
StarWind SAN and NAS v0.2 build 1914 allow remote code execution.
YüksekCVSS 8,8İstismar yokEPSS %2starwindsoftware · starwind san \& nas3 Haz 2022
- CVE-2022-2385835İzleyin
A flaw was found in the REST API.
YüksekCVSS 8,8İstismar yokEPSS %1starwindsoftware · command center23 Oca 2022
- CVE-2022-2455135İzleyin
A flaw was found in StarWind Stack.
YüksekCVSS 8,8İstismar yokEPSS %1starwindsoftware · nas6 Şub 2022
- CVE-2020-3638531İzleyin
An issue was discovered in the Linux kernel before 5.10.
YüksekCVSS 7,8İstismar yokEPSS %1linux · linux kernel7 Haz 2021
- CVE-2020-1440931İzleyin
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SD
YüksekCVSS 7,8İstismar yokEPSS %1libsdl · simple directmedia layer19 Oca 2021
- CVE-2007-2000130İzleyin
A flaw was found in StarWind iSCSI target.
YüksekCVSS 7,5İstismar yokEPSS %1starwindsoftware · iscsi san6 Şub 2022
- CVE-2020-2564329İzleyin
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7.
YüksekCVSS 7,2İstismar yokEPSS %3linux · linux kernel6 Eki 2020
- CVE-2021-4161729İzleyin
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplement
YüksekCVSS 7,0Kavram kanıtıEPSS %3openbsd · openssh26 Eyl 2021
- CVE-2021-2027128İzleyin
A flaw was found in RPM's signature check functionality when reading a package file.
YüksekCVSS 7,0İstismar yokEPSS %1rpm · rpm26 Mar 2021
- CVE-2020-2439428İzleyin
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesys
YüksekCVSS 7,1İstismar yokEPSS %0linux · linux kernel19 Ağu 2020
- CVE-2018-1858427İzleyin
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Qua
OrtaCVSS 6,5İstismar yokEPSS %3cabextract project · cabextract22 Eki 2018
- CVE-2021-3775027İzleyin
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/
OrtaCVSS 6,5İstismar yokEPSS %2mit · kerberos 523 Ağu 2021
- CVE-2021-4273926İzleyin
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers
OrtaCVSS 6,7İstismar yokEPSS %0linux · linux kernel20 Eki 2021
- CVE-2018-1675823İzleyin
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the
OrtaCVSS 5,9İstismar yokEPSS %1tinc-vpn · tinc10 Eki 2018
- CVE-2018-383722İzleyin
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2
OrtaCVSS 5,5İstismar yokEPSS %1libsdl · sdl image10 Nis 2018
- CVE-2020-042722İzleyin
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.
OrtaCVSS 5,5İstismar yokEPSS %0google · android17 Eyl 2020
- CVE-2020-3632222İzleyin
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel14 Nis 2021
- CVE-2020-1431422İzleyin
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a direc
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel15 Eyl 2020
- CVE-2020-2570422İzleyin
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER.
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel1 Ara 2020