Vulnerabilidades em [UNKNOWN]

240 resultados
Análise Vexday

Com 240 CVEs catalogadas e taxa de exploração ativa em linha com a média geral do catálogo, o perfil deste vendor não apresenta desvios alarmantes em volume, mas concentra atenção em pontos específicos. O valor máximo de EPSS observado (0,9179) indica que ao menos uma vulnerabilidade possui probabilidade muito elevada de exploração, e a CVE em exploração ativa confirmada pelo CISA KEV — CVE-2018-14667, com EPSS de 0,7417 — representa risco concreto e imediato, especialmente por ser uma falha com anos de exposição ainda não completamente mitigada em ambientes desatualizados. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão que frequentemente viabiliza execução remota de código e injeção de dados maliciosos, e cuja presença recorrente sugere lacunas sistêmicas no tratamento de entradas. Com 11 CVEs com PoC pública e 7 de severidade crítica, equipes de segurança devem priorizar a verificação de exposição às vulnerabilidades com maior EPSS, mesmo na ausência de novas CVEs nos últimos 90 dias.

CVE-2018-16883LOWsssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parEPSS 0.4%CVE-2020-10722MEDIUMA vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could resulEPSS 0.4%CVE-2020-10723MEDIUMA memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payloadEPSS 0.4%CVE-2016-2121MEDIUMA permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitiveEPSS 0.4%CVE-2017-2622MEDIUMAn accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readableEPSS 0.4%CVE-2019-3827HIGHAn incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files byEPSS 0.4%CVE-2020-10773MEDIUMA stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to theEPSS 0.4%CVE-2018-16837HIGHAnsible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passEPSS 0.4%CVE-2018-1075MEDIUMovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run andEPSS 0.4%CVE-2020-10724MEDIUMA vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, pEPSS 0.4%CVE-2019-3866MEDIUMAn information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were mEPSS 0.3%CVE-2018-14625MEDIUMA flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A rEPSS 0.3%CVE-2017-2665MEDIUMThe skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.EPSS 0.3%CVE-2019-14865MEDIUMA flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example byEPSS 0.3%CVE-2018-1113MEDIUMsetup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This vioEPSS 0.3%CVE-2020-1709HIGHA vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etcEPSS 0.3%CVE-2019-19345HIGHA vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the EPSS 0.3%CVE-2020-1707HIGHA vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in theEPSS 0.3%CVE-2019-14890HIGHA vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentiEPSS 0.2%CVE-2020-10706MEDIUMA flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This fEPSS 0.1%