İçeriğe atla
Noroxi

Stormshield kayıtları

stormshield üreticisine ait 60 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%25
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

60 kayıt
  • CVE-2022-32214
    51Planlayın

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    OrtaCVSS 6,5İstismar yokEPSS %82

    llhttp · llhttp14 Tem 2022

  • CVE-2023-20032
    48Planlayın

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file p

    KritikCVSS 9,8İstismar yokEPSS %29

    clamav · clamav1 Mar 2023

  • CVE-2022-32215
    47Planlayın

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    OrtaCVSS 6,5İstismar yokEPSS %69

    llhttp · llhttp14 Tem 2022

  • CVE-2023-0286
    47Planlayın

    X.400 address type confusion in X.509 GeneralName

    YüksekCVSS 7,4İstismar yokEPSS %60

    openssl · openssl8 Şub 2023

  • CVE-2022-37434
    45Planlayın

    zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.

    KritikCVSS 9,8Kavram kanıtıEPSS %19

    zlib · zlib5 Ağu 2022

  • CVE-2020-7465
    40Planlayın

    The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Caus

    KritikCVSS 9,8İstismar yokEPSS %3

    mpd project · mpd6 Eki 2020

  • CVE-2021-45090
    40Planlayın

    Stormshield Endpoint Security before 2.1.2 allows remote code execution.

    KritikCVSS 9,8İstismar yokEPSS %3

    stormshield · endpoint security21 Ara 2021

  • CVE-2021-31617
    40Planlayın

    In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    stormshield · stormshield network security31 Oca 2022

  • CVE-2022-32213
    39İzleyin

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he

    OrtaCVSS 6,5İstismar yokEPSS %44

    llhttp · llhttp14 Tem 2022

  • CVE-2002-20001
    37İzleyin

    The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pub

    YüksekCVSS 7,5Kavram kanıtıEPSS %25

    balasys · dheater11 Kas 2021

  • CVE-2022-4450
    36İzleyin

    Double free after calling PEM_read_bio_ex

    YüksekCVSS 7,5İstismar yokEPSS %20

    openssl · openssl8 Şub 2023

  • CVE-2018-20850
    32İzleyin

    Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.

    YüksekCVSS 8,2İstismar yokEPSS %0

    stormshield · stormshield network security4 Tem 2019

  • CVE-2023-0215
    31İzleyin

    Use-after-free following BIO_new_NDEF

    YüksekCVSS 7,5İstismar yokEPSS %4

    openssl · openssl8 Şub 2023

  • CVE-2020-7466
    31İzleyin

    The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the

    YüksekCVSS 7,5İstismar yokEPSS %2

    mpd project · mpd6 Eki 2020

  • CVE-2023-0216
    31İzleyin

    Invalid pointer dereference in d2i_PKCS7 functions

    YüksekCVSS 7,5İstismar yokEPSS %2

    openssl · openssl8 Şub 2023

  • CVE-2023-0401
    31İzleyin

    NULL dereference during PKCS7 data verification

    YüksekCVSS 7,5İstismar yokEPSS %2

    openssl · openssl8 Şub 2023

  • CVE-2022-40617
    31İzleyin

    strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and i

    YüksekCVSS 7,5İstismar yokEPSS %2

    strongswan · strongswan31 Eki 2022

  • CVE-2021-27932
    31İzleyin

    Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

    YüksekCVSS 7,8İstismar yokEPSS %0

    stormshield · ssl vpn client25 Ağu 2023

  • CVE-2022-46782
    31İzleyin

    An issue was discovered in Stormshield SSL VPN Client before 3.2.0.

    YüksekCVSS 7,8İstismar yokEPSS %0

    stormshield · ssl vpn client4 Ağu 2023

  • CVE-2021-28665
    30İzleyin

    Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive c

    YüksekCVSS 7,5İstismar yokEPSS %1

    stormshield · network security6 May 2021

  • CVE-2022-30279
    30İzleyin

    An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.

    YüksekCVSS 7,5İstismar yokEPSS %1

    stormshield · stormshield network security12 May 2022

  • CVE-2021-28127
    30İzleyin

    An issue was discovered in Stormshield SNS through 4.2.1.

    YüksekCVSS 7,5İstismar yokEPSS %1

    stormshield · stormshield network security1 Tem 2021

  • CVE-2022-23989
    30İzleyin

    In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood

    YüksekCVSS 7,5İstismar yokEPSS %1

    stormshield · stormshield network security15 Mar 2022

  • CVE-2021-45885
    30İzleyin

    An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).

    YüksekCVSS 7,5İstismar yokEPSS %1

    stormshield · network security29 Ara 2021

  • CVE-2022-27812
    30İzleyin

    Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lea

    YüksekCVSS 7,5İstismar yokEPSS %1

    stormshield · stormshield network security24 Ağu 2022