Show filters
649 Total Results
Displaying 111-120 of 649
Sort by:
Attacker Value
Unknown

CVE-2022-28331

Disclosure Date: January 31, 2023 (last updated February 24, 2025)
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.
Attacker Value
Unknown

CVE-2022-25147

Disclosure Date: January 31, 2023 (last updated February 24, 2025)
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
Attacker Value
Unknown

CVE-2022-24963

Disclosure Date: January 31, 2023 (last updated February 24, 2025)
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.
Attacker Value
Unknown

CVE-2020-12069

Disclosure Date: December 26, 2022 (last updated February 24, 2025)
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Attacker Value
Unknown

CVE-2022-30694

Disclosure Date: November 08, 2022 (last updated February 24, 2025)
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
Attacker Value
Unknown

CVE-2022-1319

Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
Attacker Value
Unknown

CVE-2022-1259

Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
Attacker Value
Unknown

CVE-2021-3914

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
Attacker Value
Unknown

CVE-2021-4178

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Attacker Value
Unknown

CVE-2021-3690

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.