Ossec
Ossec: vulnerabilidades y CVE
Ossec tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-28040 | Alta (7.5) | 1.2% | — | 5 mar 2021 | An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tags is used. Because recursion is used in _ReadElem without restriction,… |
| CVE-2020-8448 | Media (5.5) | 0.49% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written directly to the analysisd… |
| CVE-2020-8447 | Crítica (9.8) | 1.9% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote… |
| CVE-2020-8446 | Media (5.5) | 0.50% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd… |
| CVE-2020-8445 | Crítica (9.8) | 2.3% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later… |
| CVE-2020-8444 | Crítica (9.8) | 2.5% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted msgs (received from authenticated remote… |
| CVE-2020-8443 | Crítica (9.8) | 2.7% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from… |
| CVE-2020-8442 | Alta (8.8) | 2.4% | — | 30 ene 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client. |
| CVE-2018-19666 | Alta (7.8) | 0.78% | — | 29 nov 2018 | The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server. |
| CVE-2015-3222 | Alta (7) | 2.0% | — | 7 sept 2017 | syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root. |
| CVE-2014-5284 | Alta (7.2) | 2.4% | — | 2 dic 2014 | host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by… |