Vulnerabilidades em [UNKNOWN]

239 resultados
Análise Vexday

Com 240 CVEs catalogadas e taxa de exploração ativa em linha com a média geral do catálogo, o perfil deste vendor não apresenta desvios alarmantes em volume, mas concentra atenção em pontos específicos. O valor máximo de EPSS observado (0,9179) indica que ao menos uma vulnerabilidade possui probabilidade muito elevada de exploração, e a CVE em exploração ativa confirmada pelo CISA KEV — CVE-2018-14667, com EPSS de 0,7417 — representa risco concreto e imediato, especialmente por ser uma falha com anos de exposição ainda não completamente mitigada em ambientes desatualizados. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão que frequentemente viabiliza execução remota de código e injeção de dados maliciosos, e cuja presença recorrente sugere lacunas sistêmicas no tratamento de entradas. Com 11 CVEs com PoC pública e 7 de severidade crítica, equipes de segurança devem priorizar a verificação de exposição às vulnerabilidades com maior EPSS, mesmo na ausência de novas CVEs nos últimos 90 dias.

CVE-2017-7467HIGHA buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could pEPSS 2.7%CVE-2016-8627MEDIUMadmin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be availEPSS 2.6%CVE-2017-2668MEDIUM389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled.EPSS 2.6%CVE-2019-3826MEDIUMA stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincEPSS 2.6%CVE-2018-14663MEDIUMAn issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the adEPSS 2.6%CVE-2018-14660MEDIUMA flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authEPSS 2.5%CVE-2018-14624HIGHA vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not coEPSS 2.5%CVE-2020-1700MEDIUMA flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by maEPSS 2.4%CVE-2019-14853LOWAn error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexEPSS 2.4%CVE-2018-16854MEDIUMA flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by EPSS 2.3%CVE-2018-16857HIGHSamba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of paEPSS 2.3%CVE-2018-14621MEDIUMAn infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion ofEPSS 2.3%CVE-2018-1085CRITICALopenshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to EPSS 2.2%CVE-2018-16852MEDIUMSamba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the EPSS 2.2%CVE-2019-3847MEDIUMA vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such aEPSS 2.2%CVE-2018-10877HIGHLinux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 fEPSS 2.2%CVE-2020-10725HIGHA flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend appliEPSS 2.2%CVE-2017-7470MEDIUMIt was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect auEPSS 2.1%CVE-2018-16846MEDIUMIt was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indEPSS 2.1%CVE-2017-2673MEDIUMAn authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federEPSS 2.1%