یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 4,292 نتیجه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

زیاد CVSS 7.5 اولویت 41

CVE-2017-6632 — CVE-2017-6632 — firepower threat defense

A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain TCP packets by the affected…

cisco / firepower threat defense
2017-05-2201:29
1 منبع · 1 رسمی اعتماد متوسط · 50/100 نیازمند توجه · 55/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.1 اولویت 39

CVE-2017-6625 — CVE-2017-6625 — secure firewall threat defense

A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a denial of service (DoS) condition. The…

cisco / secure firewall threat defense
2017-05-0321:59
1 منبع · 1 رسمی اعتماد متوسط · 50/100 نیازمند توجه · 55/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 5.9 اولویت 32

CVE-2017-3887 — CVE-2017-3887 — secure firewall threat defense

A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly restarts. This vulnerability affects Cisco Firepower System Software prior to the first fixed release…

cisco / secure firewall threat defense
2017-04-0717:59
1 منبع · 1 رسمی اعتماد متوسط · 50/100 نیازمند توجه · 55/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 5.3 اولویت 29

CVE-2017-3822 — CVE-2017-3822 — secure firewall threat defense

A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Defense Software versions 6.1.x on the following vulnerable products that have enabled FDM: ASA5506-X…

cisco / secure firewall threat defense
2017-02-0307:59
1 منبع · 1 رسمی اعتماد متوسط · 50/100 نیازمند توجه · 55/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 5.3 اولویت 29

CVE-2017-3806 — CVE-2017-3806 — secure firewall threat defense

A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. More Information: CSCvb61343. Known Affected Releases: 2.0(1.68). Known Fixed Releases: 2.0(1.118)…

cisco / secure firewall threat defense
2017-02-0307:59
1 منبع · 1 رسمی اعتماد متوسط · 50/100 نیازمند توجه · 55/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 98.5% اولویت 99

CVE-2012-4681 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted…

Oracle / oracle / jdk Oracle / Java SE
2012-08-2800:55
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 93.7% اولویت 97

CVE-2012-1723 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Oracle / oracle / jdk Oracle / Java SE
2012-06-1621:55
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
متوسط CISA KEV CVSS 6.5 EPSS 90.0% اولویت 78

CVE-2009-3960 — Adobe BlazeDS Information Disclosure Vulnerability

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external…

adobe / blazeds
2010-02-1518:30
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
نامشخص اولویت 8

OpenSSH Security Advisory

May 21, 2001: OpenSSH 2.9.9 and newer are not vulnerable to "Sep 26, 2001: Weakness in OpenSSH's source IP based access control for SSH protocol v2 public key authentication.", OpenSSH Security Advisory.

OpenSSH / OpenSSH
2001-05-2100:00
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 8

OpenBSD Security Advisory

November 6, 2000: OpenSSH 2.3.1, a development snapshot which was never released, was vulnerable to "Feb 8, 2001: Authentication By-Pass Vulnerability in OpenSSH-2.3.1", OpenBSD Security Advisory. In protocol 2, authentication could be bypassed if public key authentication was permitted. This problem does exist only in OpenSSH 2.3.1, a three week internal…

OpenSSH / OpenSSH
2001-02-0800:00
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
نامشخص اولویت 8

Crimelabs Security Note CLABS200101

OpenSSH was never vulnerable to the "Feb 5, 2001: SSH-1 Brute Force Password Vulnerability", Crimelabs Security Note CLABS200101.

OpenSSH / OpenSSH
2001-02-0500:00
1 منبع · 1 رسمی اعتماد متوسط · 59/100 نیازمند توجه · 66/100 داده تازه جزئیات و راهکار رفع
بحرانی اولویت 46

Versioning Policy

Quick Links Support Versioning Policy Security Professional Services Hosting Solutions Report a Bug

PostgreSQL / PostgreSQL
2000-05-0800:00
1 منبع · 1 رسمی اعتماد خوب · 61/100 کیفیت خوب · 71/100 داده تازه جزئیات و راهکار رفع