Known vulnerabilities in OSSEC
Vendor:
OSSEC Project
Software:
OSSEC
Software CPE:
cpe:2.3:a:ossec_project:ossec:*:*:*:*:*:*:*:*
Website:
https://www.ossec.net/
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU102310 - Improper Output Neutralization for Logs CVE-2020-8445 |
CWE-117 | Medium | 3.6.0 | 06.01.2025 |
SB2020013018 |
||
| #VU102308 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-8446 |
CWE-22 | Low | 3.6.0 | 06.01.2025 |
SB2020013018 |
||
| #VU24780 - Use After Free CVE-2020-8444 |
CWE-416 | Medium | - | 30.01.2020 |
SB2020013019 |
||
| #VU24779 - Off-by-one Error CVE-2020-8443 |
CWE-193 | High | 3.6.0 | 30.01.2020 |
SB2020013018 |
||
| #VU24778 - Heap-based Buffer Overflow CVE-2020-8442 |
CWE-122 | High | 3.6.0 | 30.01.2020 |
SB2020013017 |
||
| #VU38351 - Permissions, Privileges, and Access Controls CVE-2015-3222 |
CWE-264 | Low | - | 07.09.2017 |
SB2017090727 |