Vulnerabilities in Talos

127 results
Vexday analysis

Com 127 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, a taxa de exploração ativa da Talos situa-se abaixo da média geral do catálogo, o que indica menor pressão de ameaças ativas no momento. No entanto, 36 vulnerabilidades classificadas como críticas representam uma superfície de risco considerável que merece atenção contínua. O tipo de falha mais recorrente é CWE-416 (Use-After-Free), categoria que historicamente favorece execução de código arbitrário e elevação de privilégios. A CVE mais perigosa identificada atualmente é CVE-2018-3949, com score EPSS de 0,533 — valor que indica probabilidade relevante de exploração —, sendo também a única com prova de conceito pública disponível, o que a torna prioritária para equipes de resposta.

CVE-2018-3848HIGHIn the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriEPSS 3.6%CVE-2019-5016CRITICALAn exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functioEPSS 3.6%CVE-2019-5067CRITICALAn uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially cEPSS 3.4%CVE-2017-14458HIGHAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013. A specEPSS 3.4%CVE-2018-3853HIGHAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9.0.1.1049. A specialEPSS 3.3%CVE-2018-3938CRITICALAn exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5EPSS 3.3%CVE-2017-2826An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy requesEPSS 3.3%CVE-2018-3842HIGHAn exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A speciEPSS 3.2%CVE-2018-3846HIGHIn the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overEPSS 3.1%CVE-2017-2888HIGHAn exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an intEPSS 3.1%CVE-2018-4056CRITICALAn exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login messaEPSS 3.0%CVE-2018-3950HIGHAn exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VPN HWv3 FRNv1.3.0 andEPSS 2.9%CVE-2018-3850HIGHAn exploitable use-after-free vulnerability exists in the JavaScript engine Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially EPSS 2.8%CVE-2017-12092LOWAn exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and befEPSS 2.7%CVE-2017-2887HIGHAn exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf fEPSS 2.7%CVE-2017-12130HIGHAn exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially crafted packet can mEPSS 2.4%CVE-2018-3835HIGHAn exploitable out of bounds write vulnerability exists in version 2.2 of the Per Face Texture mapping application known as PTEX. The vulnerEPSS 2.4%CVE-2019-5066CRITICALAn exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially cEPSS 2.4%CVE-2018-3981HIGHAn exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker can deliver a TIFF imaEPSS 2.3%CVE-2017-14435HIGHAn exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially craftEPSS 2.2%