Stormshield kayıtları
stormshield üreticisine ait 60 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %25
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference3
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-787 Out-of-bounds Write2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-284 Improper Access Control2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
60 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2022-32214İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Orta6,5 | — | %82,5 | 14 Tem 2022 |
48Planlayın | CVE-2023-20032İstismar yok | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file pclamav · clamav · CWE-120 | Kritik9,8 | — | %29,3 | 1 Mar 2023 |
47Planlayın | CVE-2022-32215İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Orta6,5 | — | %68,8 | 14 Tem 2022 |
47Planlayın | CVE-2023-0286İstismar yok | X.400 address type confusion in X.509 GeneralNameopenssl · openssl · CWE-843 | Yüksek7,4 | — | %59,5 | 8 Şub 2023 |
45Planlayın | CVE-2022-37434Kavram kanıtı | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.zlib · zlib · CWE-787 | Kritik9,8 | — | %19,0 | 5 Ağu 2022 |
40Planlayın | CVE-2020-7465İstismar yok | The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Causmpd project · mpd · CWE-787 | Kritik9,8 | — | %3,0 | 6 Eki 2020 |
40Planlayın | CVE-2021-45090İstismar yok | Stormshield Endpoint Security before 2.1.2 allows remote code execution.stormshield · endpoint security | Kritik9,8 | — | %2,9 | 21 Ara 2021 |
40Planlayın | CVE-2021-31617İstismar yok | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.stormshield · stormshield network security · CWE-119 | Kritik9,8 | — | %2,1 | 31 Oca 2022 |
39İzleyin | CVE-2022-32213İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding hellhttp · llhttp · CWE-444 | Orta6,5 | — | %44,1 | 14 Tem 2022 |
37İzleyin | CVE-2002-20001Kavram kanıtı | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pubbalasys · dheater · CWE-400 | Yüksek7,5 | — | %24,6 | 11 Kas 2021 |
36İzleyin | CVE-2022-4450İstismar yok | Double free after calling PEM_read_bio_exopenssl · openssl · CWE-415 | Yüksek7,5 | — | %20,4 | 8 Şub 2023 |
32İzleyin | CVE-2018-20850İstismar yok | Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.stormshield · stormshield network security · CWE-79 | Yüksek8,2 | — | %0,4 | 4 Tem 2019 |
31İzleyin | CVE-2023-0215İstismar yok | Use-after-free following BIO_new_NDEFopenssl · openssl · CWE-416 | Yüksek7,5 | — | %4,5 | 8 Şub 2023 |
31İzleyin | CVE-2020-7466İstismar yok | The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the mpd project · mpd · CWE-125 | Yüksek7,5 | — | %2,0 | 6 Eki 2020 |
31İzleyin | CVE-2023-0216İstismar yok | Invalid pointer dereference in d2i_PKCS7 functionsopenssl · openssl · CWE-476 | Yüksek7,5 | — | %1,8 | 8 Şub 2023 |
31İzleyin | CVE-2023-0401İstismar yok | NULL dereference during PKCS7 data verificationopenssl · openssl · CWE-476 | Yüksek7,5 | — | %1,8 | 8 Şub 2023 |
31İzleyin | CVE-2022-40617İstismar yok | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and istrongswan · strongswan · CWE-400 | Yüksek7,5 | — | %1,7 | 31 Eki 2022 |
31İzleyin | CVE-2021-27932İstismar yok | Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.stormshield · ssl vpn client | Yüksek7,8 | — | %0,2 | 25 Ağu 2023 |
31İzleyin | CVE-2022-46782İstismar yok | An issue was discovered in Stormshield SSL VPN Client before 3.2.0.stormshield · ssl vpn client | Yüksek7,8 | — | %0,2 | 4 Ağu 2023 |
30İzleyin | CVE-2021-28665İstismar yok | Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive cstormshield · network security · CWE-401 | Yüksek7,5 | — | %1,0 | 6 May 2021 |
30İzleyin | CVE-2022-30279İstismar yok | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.stormshield · stormshield network security · CWE-476 | Yüksek7,5 | — | %1,0 | 12 May 2022 |
30İzleyin | CVE-2021-28127İstismar yok | An issue was discovered in Stormshield SNS through 4.2.1.stormshield · stormshield network security · CWE-307 | Yüksek7,5 | — | %0,9 | 1 Tem 2021 |
30İzleyin | CVE-2022-23989İstismar yok | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a floodstormshield · stormshield network security | Yüksek7,5 | — | %0,9 | 15 Mar 2022 |
30İzleyin | CVE-2021-45885İstismar yok | An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).stormshield · network security · CWE-613 | Yüksek7,5 | — | %0,9 | 29 Ara 2021 |
30İzleyin | CVE-2022-27812İstismar yok | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can leastormshield · stormshield network security | Yüksek7,5 | — | %0,8 | 24 Ağu 2022 |
- CVE-2022-3221451Planlayın
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
OrtaCVSS 6,5İstismar yokEPSS %82llhttp · llhttp14 Tem 2022
- CVE-2023-2003248Planlayın
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file p
KritikCVSS 9,8İstismar yokEPSS %29clamav · clamav1 Mar 2023
- CVE-2022-3221547Planlayın
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
OrtaCVSS 6,5İstismar yokEPSS %69llhttp · llhttp14 Tem 2022
- CVE-2023-028647Planlayın
X.400 address type confusion in X.509 GeneralName
YüksekCVSS 7,4İstismar yokEPSS %60openssl · openssl8 Şub 2023
- CVE-2022-3743445Planlayın
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
KritikCVSS 9,8Kavram kanıtıEPSS %19zlib · zlib5 Ağu 2022
- CVE-2020-746540Planlayın
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Caus
KritikCVSS 9,8İstismar yokEPSS %3mpd project · mpd6 Eki 2020
- CVE-2021-4509040Planlayın
Stormshield Endpoint Security before 2.1.2 allows remote code execution.
KritikCVSS 9,8İstismar yokEPSS %3stormshield · endpoint security21 Ara 2021
- CVE-2021-3161740Planlayın
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.
KritikCVSS 9,8İstismar yokEPSS %2stormshield · stormshield network security31 Oca 2022
- CVE-2022-3221339İzleyin
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he
OrtaCVSS 6,5İstismar yokEPSS %44llhttp · llhttp14 Tem 2022
- CVE-2002-2000137İzleyin
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pub
YüksekCVSS 7,5Kavram kanıtıEPSS %25balasys · dheater11 Kas 2021
- CVE-2022-445036İzleyin
Double free after calling PEM_read_bio_ex
YüksekCVSS 7,5İstismar yokEPSS %20openssl · openssl8 Şub 2023
- CVE-2018-2085032İzleyin
Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.
YüksekCVSS 8,2İstismar yokEPSS %0stormshield · stormshield network security4 Tem 2019
- CVE-2023-021531İzleyin
Use-after-free following BIO_new_NDEF
YüksekCVSS 7,5İstismar yokEPSS %4openssl · openssl8 Şub 2023
- CVE-2020-746631İzleyin
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the
YüksekCVSS 7,5İstismar yokEPSS %2mpd project · mpd6 Eki 2020
- CVE-2023-021631İzleyin
Invalid pointer dereference in d2i_PKCS7 functions
YüksekCVSS 7,5İstismar yokEPSS %2openssl · openssl8 Şub 2023
- CVE-2023-040131İzleyin
NULL dereference during PKCS7 data verification
YüksekCVSS 7,5İstismar yokEPSS %2openssl · openssl8 Şub 2023
- CVE-2022-4061731İzleyin
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and i
YüksekCVSS 7,5İstismar yokEPSS %2strongswan · strongswan31 Eki 2022
- CVE-2021-2793231İzleyin
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
YüksekCVSS 7,8İstismar yokEPSS %0stormshield · ssl vpn client25 Ağu 2023
- CVE-2022-4678231İzleyin
An issue was discovered in Stormshield SSL VPN Client before 3.2.0.
YüksekCVSS 7,8İstismar yokEPSS %0stormshield · ssl vpn client4 Ağu 2023
- CVE-2021-2866530İzleyin
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive c
YüksekCVSS 7,5İstismar yokEPSS %1stormshield · network security6 May 2021
- CVE-2022-3027930İzleyin
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.
YüksekCVSS 7,5İstismar yokEPSS %1stormshield · stormshield network security12 May 2022
- CVE-2021-2812730İzleyin
An issue was discovered in Stormshield SNS through 4.2.1.
YüksekCVSS 7,5İstismar yokEPSS %1stormshield · stormshield network security1 Tem 2021
- CVE-2022-2398930İzleyin
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood
YüksekCVSS 7,5İstismar yokEPSS %1stormshield · stormshield network security15 Mar 2022
- CVE-2021-4588530İzleyin
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).
YüksekCVSS 7,5İstismar yokEPSS %1stormshield · network security29 Ara 2021
- CVE-2022-2781230İzleyin
Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lea
YüksekCVSS 7,5İstismar yokEPSS %1stormshield · stormshield network security24 Ağu 2022