Show filters
561 Total Results
Displaying 111-120 of 561
Sort by:
Attacker Value
Unknown

CVE-2023-23954

Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2023-23953

Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.
Attacker Value
Unknown

CVE-2023-23952

Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
Attacker Value
Unknown

CVE-2023-23956

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
Attacker Value
Unknown

CVE-2023-27538

Disclosure Date: March 30, 2023 (last updated March 28, 2024)
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.
Attacker Value
Unknown

CVE-2023-27537

Disclosure Date: March 30, 2023 (last updated March 28, 2024)
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
Attacker Value
Unknown

CVE-2023-27534

Disclosure Date: March 30, 2023 (last updated March 28, 2024)
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.
Attacker Value
Unknown

CVE-2023-27789

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.
Attacker Value
Unknown

CVE-2023-27788

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
Attacker Value
Unknown

CVE-2023-27787

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.