CVE-2021-28040
- EPSS 1.19%
- Veröffentlicht 05.03.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:59:01
An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tags is used. Because recursion is used in _ReadElem without restriction, an attacker can trigger a segm...
CVE-2020-8447
- EPSS 1.94%
- Veröffentlicht 30.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:52
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analys...
CVE-2020-8448
- EPSS 0.49%
- Veröffentlicht 30.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:52
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written directly to the analysisd UNIX domain socket by a local ...
CVE-2020-8442
- EPSS 2.39%
- Veröffentlicht 30.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:51
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.
CVE-2020-8443
- EPSS 2.69%
- Veröffentlicht 30.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:51
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote agents and d...
CVE-2020-8444
- EPSS 2.49%
- Veröffentlicht 30.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:52
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted msgs (received from authenticated remote agents and delivered to the ana...
- EPSS 2.28%
- Veröffentlicht 30.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:52
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are per...
CVE-2020-8446
- EPSS 0.5%
- Veröffentlicht 30.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:52
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local use...
CVE-2018-19666
- EPSS 0.78%
- Veröffentlicht 29.11.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:23
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server.
- EPSS 1.99%
- Veröffentlicht 07.09.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.