Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown

CVE-2022-27812

Disclosure Date: August 24, 2022 (last updated August 21, 2024)
Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS.
Attacker Value
Unknown

CVE-2022-37434

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
Attacker Value
Unknown

CVE-2022-30279

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash.
Attacker Value
Unknown

CVE-2022-23989

Disclosure Date: March 15, 2022 (last updated August 21, 2024)
In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface. This could result in the blocking of almost all network traffic, making the firewall unreachable. An attacker could exploit this via forged and properly timed traffic to cause a denial of service.
Attacker Value
Unknown

CVE-2022-0211

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Attacker Value
Unknown

CVE-2021-3398

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.
Attacker Value
Unknown

CVE-2021-37613

Disclosure Date: February 10, 2022 (last updated October 07, 2023)
Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.
Attacker Value
Unknown

CVE-2021-31814

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.
Attacker Value
Unknown

CVE-2021-31617

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.
Attacker Value
Unknown

CVE-2021-28962

Disclosure Date: January 31, 2022 (last updated August 21, 2024)
Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.