Management Services For Element Software

Vendor:

First CVE: Feb 26, 2021 · Active for 5 years

27
Total CVEs
More Total CVEs than 96% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Management Services For Element Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 26, 2021
5 years ago
Most Recent CVE
Aug 7, 2023
1,082 days ago

CVE Severity & Scoring

Management Services For Element Software27 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local3 (11.1%)
Network24 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (81.5%)
High5 (18.5%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low10 (37.0%)
High1 (3.7%)
None16 (59.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB
Jun 9, 20215.374NOYES
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Mar 25, 20227.556NONO
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHe
Aug 5, 20229.841NONO
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Feb 17, 20237.535NONO
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be ov
Oct 4, 20218.835NONO
Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specifi
Oct 4, 20217.532NONO
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt t
Oct 4, 20217.531NONO
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023
Jul 25, 20239.830NONO
Netlogon RPC Elevation of Privilege Vulnerability
Nov 9, 20228.130NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Management Services For Element Software

Top CWEs

Versions

No cataloged versions.