Show filters
43 Total Results
Displaying 11-20 of 43
Sort by:
Attacker Value
Unknown
CVE-2022-47925
Disclosure Date: March 27, 2023 (last updated February 15, 2024)
The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a partial DoS of the service. Only the request of the attacker is affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2022-47924
Disclosure Date: March 27, 2023 (last updated November 08, 2023)
An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally installed Secvisogram in versions < 0.1.0 wich can result in arbitrary code execution and DoS once the users triggers the validation.
0
Attacker Value
Unknown
CVE-2021-4295
Disclosure Date: December 29, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the component XML Handler. The manipulation leads to xml external entity reference. Upgrading to version 1.0.31 is able to address this issue. The name of the patch is fbd8ea121755a2d3d116b13f235bc8b61d8449af. It is recommended to upgrade the affected component. VDB-217018 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-40901
Disclosure Date: June 27, 2022 (last updated October 07, 2023)
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.
0
Attacker Value
Unknown
CVE-2021-43114
Disclosure Date: November 09, 2021 (last updated February 23, 2025)
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
0
Attacker Value
Unknown
CVE-2021-3765
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
validator.js is vulnerable to Inefficient Regular Expression Complexity
0
Attacker Value
Unknown
CVE-2020-7779
Disclosure Date: November 26, 2020 (last updated February 22, 2025)
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.
0
Attacker Value
Unknown
CVE-2020-7767
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls.
0
Attacker Value
Unknown
CVE-2020-17479
Disclosure Date: August 10, 2020 (last updated February 21, 2025)
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
0
Attacker Value
Unknown
CVE-2020-16164
Disclosure Date: July 30, 2020 (last updated February 21, 2025)
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation List files from the RPKI relying party's view. NOTE: some third parties may regard this as a preferred behavior, not a vulnerability
0