Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ossec HIGH 7.5
CVE-2021-28040

An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tag…

No fix yet
Fix from $1,950 2021-03-05
Ossec CRITICAL 9.8
CVE-2020-8447

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during process…

Fix: after 3.5.0
Fix from $2,300 2020-01-30
Ossec MEDIUM 5.5
CVE-2020-8448

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL point…

Fix: after 3.5.0
Fix from $1,600 2020-01-30
Ossec CRITICAL 9.8
CVE-2020-8443

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer…

Fix: after 3.5.0
Fix from $2,300 2020-01-30
Ossec CRITICAL 9.8
CVE-2020-8444

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during process…

Fix: after 3.5.0
Fix from $2,300 2020-01-30
Ossec CRITICAL 9.8
CVE-2020-8445

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from pr…

Fix: after 3.5.0
Fix from $2,300 2020-01-30
Ossec HIGH 8.8
CVE-2020-8442

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in…

Fix: after 3.5.0
Fix from $1,950 2020-01-30
Ossec MEDIUM 5.5
CVE-2020-8446

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write acce…

Fix: after 3.5.0
Fix from $1,600 2020-01-30
Ossec HIGH 7.8
CVE-2018-19666

The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access t…

Fix: after 3.1.0
Fix from $1,950 2018-11-29
Ossec HIGH 7.0
CVE-2015-3222

syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

No fix yet
Fix from $1,950 2017-09-07
Web Ui MEDIUM 6.1
CVE-2016-4847

Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML…

Fix: after 0.8
Fix from $1,600 2017-04-20
Ossec HIGH 7.2
CVE-2014-5284

host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modi…

Fix: after 2.8.0
Fix from $1,950 2014-12-02