suse kayıtları
suse üreticisine ait 1.205 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 48 · %4
- Silahlaştırılmış
- 63 · %5,2
- Pre-auth RCE
- 265
- Düzeltme kaydı olan
- %78,4
- Yayından KEV’e ortanca
- 2796 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer97
- CWE-416 Use After Free68
- CWE-787 Out-of-bounds Write61
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor42
- CWE-476 NULL Pointer Dereference37
- CWE-20 Improper Input Validation35
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
1.205 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2015-3113Silahlaştırılmış | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Kritik9,8 | KEV | %99,9 | 23 Haz 2015 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
99Hemen | CVE-2014-0497Silahlaştırılmış | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Kritik9,8 | KEV | %99,9 | 5 Şub 2014 |
99Hemen | CVE-2015-5119Silahlaştırılmış | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Kritik9,8 | KEV | %99,3 | 8 Tem 2015 |
99Hemen | CVE-2013-2465Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Kritik9,8 | KEV | %98,8 | 18 Haz 2013 |
98Hemen | CVE-2012-0507Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Kritik9,8 | KEV | %98,1 | 7 Haz 2012 |
98Hemen | CVE-2011-3544Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Kritik9,8 | KEV | %96,7 | 19 Eki 2011 |
98Hemen | CVE-2015-0313Silahlaştırılmış | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Kritik9,8 | KEV | %95,3 | 2 Şub 2015 |
97Hemen | CVE-2016-4117Silahlaştırılmış | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Kritik9,8 | KEV | %94,4 | 10 May 2016 |
97Hemen | CVE-2015-5122Silahlaştırılmış | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Kritik9,8 | KEV | %94,0 | 14 Tem 2015 |
97Hemen | CVE-2016-3427Silahlaştırılmış | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Kritik9,8 | KEV | %92,3 | 21 Nis 2016 |
96Hemen | CVE-2012-5076Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers toracle · jre · CWE-284 | Kritik9,8 | KEV | %91,3 | 16 Eki 2012 |
95Hemen | CVE-2011-0611Silahlaştırılmış | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Yüksek8,8 | KEV | %99,4 | 13 Nis 2011 |
95Hemen | CVE-2015-0311Silahlaştırılmış | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throuadobe · flash player | Kritik9,8 | KEV | %85,6 | 23 Oca 2015 |
92Hemen | CVE-2016-3714Silahlaştırılmış | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | Yüksek8,4 | KEV | %97,5 | 5 May 2016 |
90Hemen | CVE-2009-3953Silahlaştırılmış | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | Yüksek8,8 | KEV | %83,2 | 13 Oca 2010 |
89Hemen | CVE-2016-0752Silahlaştırılmış | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, anrubyonrails · rails · CWE-22 | Yüksek7,5 | KEV | %95,5 | 15 Şub 2016 |
89Hemen | CVE-2021-4034Silahlaştırılmış | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Yüksek7,8 | KEV | %94,3 | 28 Oca 2022 |
89Hemen | CVE-2013-2729Silahlaştırılmış | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitadobe · acrobat · CWE-190 | Kritik9,8 | KEV | %66,6 | 16 May 2013 |
87Hemen | CVE-2013-0640Silahlaştırılmış | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | Yüksek7,8 | KEV | %86,9 | 13 Şub 2013 |
86Hemen | CVE-2010-1297Silahlaştırılmış | Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,adobe · air · CWE-787 | Yüksek7,8 | KEV | %82,5 | 8 Haz 2010 |
86Hemen | CVE-2009-4324Silahlaştırılmış | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | Yüksek7,8 | KEV | %81,9 | 14 Ara 2009 |
86Hemen | CVE-2013-1690Silahlaştırılmış | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Yüksek8,8 | KEV | %69,0 | 25 Haz 2013 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2015-311399Hemen
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player23 Haz 2015
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-049799Hemen
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · flash player5 Şub 2014
- CVE-2015-511999Hemen
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99adobe · flash player8 Tem 2015
- CVE-2013-246599Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99oracle · jre18 Haz 2013
- CVE-2012-050798Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98oracle · jre7 Haz 2012
- CVE-2011-354498Hemen
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97oracle · jdk19 Eki 2011
- CVE-2015-031398Hemen
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95adobe · flash player2 Şub 2015
- CVE-2016-411797Hemen
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · flash player10 May 2016
- CVE-2015-512297Hemen
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · flash player14 Tem 2015
- CVE-2016-342797Hemen
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92oracle · jdk21 Nis 2016
- CVE-2012-507696Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %91oracle · jre16 Eki 2012
- CVE-2011-061195Hemen
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99adobe · flash player13 Nis 2011
- CVE-2015-031195Hemen
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and throu
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %86adobe · flash player23 Oca 2015
- CVE-2016-371492Hemen
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %97imagemagick · imagemagick5 May 2016
- CVE-2009-395390Hemen
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %83adobe · acrobat13 Oca 2010
- CVE-2016-075289Hemen
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, an
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %96rubyonrails · rails15 Şub 2016
- CVE-2021-403489Hemen
A local privilege escalation vulnerability was found on polkit's pkexec utility.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %94polkit project · polkit28 Oca 2022
- CVE-2013-272989Hemen
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbit
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %67adobe · acrobat16 May 2013
- CVE-2013-064087Hemen
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %87adobe · acrobat13 Şub 2013
- CVE-2010-129786Hemen
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3,
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %83adobe · air8 Haz 2010
- CVE-2009-432486Hemen
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %82adobe · acrobat14 Ara 2009
- CVE-2013-169086Hemen
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69mozilla · firefox25 Haz 2013