Show filters
820 Total Results
Displaying 111-120 of 820
Sort by:
Attacker Value
Unknown
CVE-2023-27534
Disclosure Date: March 30, 2023 (last updated March 28, 2024)
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.
0
Attacker Value
Unknown
CVE-2023-27533
Disclosure Date: March 30, 2023 (last updated March 28, 2024)
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2023-28487
Disclosure Date: March 16, 2023 (last updated November 02, 2023)
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
0
Attacker Value
Unknown
CVE-2023-28486
Disclosure Date: March 16, 2023 (last updated November 02, 2023)
Sudo before 1.9.13 does not escape control characters in log messages.
0
Attacker Value
Unknown
CVE-2022-23240
Disclosure Date: February 28, 2023 (last updated October 08, 2023)
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-23239
Disclosure Date: February 28, 2023 (last updated October 08, 2023)
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows administrative users to perform a Stored Cross-Site Scripting (XSS) attack.
0
Attacker Value
Unknown
CVE-2023-23915
Disclosure Date: February 23, 2023 (last updated March 28, 2024)
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.
0
Attacker Value
Unknown
CVE-2023-23914
Disclosure Date: February 23, 2023 (last updated March 28, 2024)
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
0
Attacker Value
Unknown
CVE-2023-0482
Disclosure Date: February 17, 2023 (last updated February 11, 2025)
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
0
Attacker Value
Unknown
CVE-2023-24329
Disclosure Date: February 17, 2023 (last updated October 08, 2023)
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
0