Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2022-35631
Disclosure Date: July 26, 2022 (last updated October 08, 2023)
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.
0
Attacker Value
Unknown
CVE-2022-35632
Disclosure Date: July 26, 2022 (last updated October 08, 2023)
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.
0
Attacker Value
Unknown
CVE-2021-3619
Disclosure Date: June 21, 2021 (last updated November 28, 2024)
Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly always reserved for trusted and verified users with IT security backgrounds.
0
Attacker Value
Unknown
CVE-2020-25713
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
0
Attacker Value
Unknown
CVE-2017-18926
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
0
Attacker Value
Unknown
CVE-2012-0037
Disclosure Date: June 17, 2012 (last updated February 15, 2024)
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
0
Attacker Value
Unknown
CVE-2005-0817
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.
0
Attacker Value
Unknown
CVE-2004-0369
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.
0
Attacker Value
Unknown
CVE-2002-1463
Disclosure Date: June 09, 2003 (last updated February 22, 2025)
Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.
0
Attacker Value
Unknown
CVE-2002-1535
Disclosure Date: March 31, 2003 (last updated February 22, 2025)
Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.
0