Josh Bressers
First CVE: Apr 3, 2017Active for: 9 years
162
CVEs Published
More CVEs Published than 76% of tracked CNAs
81.0
Avg CVEs / Year
More Avg CVEs / Year than 88% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Josh Bressers over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2017
9 years ago
Most Recent CVE
Oct 15, 2019
2,474 days ago
Top CVEs
All CVEs published by Josh Bressers as a CNA, regardless of affected vendor or product.
162 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1001000HIGH The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identi | Apr 3, 2017 | 7.5 | 79 | NO | YES |
CVE-2019-1010238CRITICAL Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_ | Jul 19, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-1010060CRITICAL NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: | Jul 16, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-1010298CRITICAL Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed ver | Jul 15, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-1010174CRITICAL CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image f | Jul 25, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-1010228CRITICAL OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress( | Jul 22, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-1010044CRITICAL borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable. | Jul 15, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-1010306CRITICAL Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component | Jul 15, 2019 | 9.8 | 32 | NO | NO |
CVE-2017-1001002CRITICAL math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution. | Nov 27, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-1010161CRITICAL perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decod | Jul 25, 2019 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA162 CVEs
42%
28%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local23 (14.2%)
Network138 (85.2%)
Unknown0 (0.0%)
Physical1 (0.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low160 (98.8%)
High2 (1.2%)
Unknown0 (0.0%)
User Interaction
None99 (61.1%)
Unknown0 (0.0%)
Required63 (38.9%)
Privileges Required
Low20 (12.3%)
High5 (3.1%)
None137 (84.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (162 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.6% of CVEs· 84th percentile
Nuclei
2 CVEs
1.2% of CVEs· 82nd percentile
ExploitDB
1 CVE
0.6% of CVEs· 78th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Josh Bressers as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Josh Bressers as a CNA — matched by CVE ID, not by organization name.