Show filters
102 Total Results
Displaying 31-40 of 102
Sort by:
Attacker Value
Unknown
CVE-2023-28507
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
0
Attacker Value
Unknown
CVE-2023-28506
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.
0
Attacker Value
Unknown
CVE-2023-28505
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.
0
Attacker Value
Unknown
CVE-2023-28504
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
0
Attacker Value
Unknown
CVE-2023-28503
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
0
Attacker Value
Unknown
CVE-2023-28502
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.
0
Attacker Value
Unknown
CVE-2023-28501
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
0
Attacker Value
Unknown
CVE-2023-23911
Disclosure Date: March 10, 2023 (last updated October 08, 2023)
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.
0
Attacker Value
Unknown
CVE-2023-23917
Disclosure Date: February 23, 2023 (last updated October 08, 2023)
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack vector also may increase the impact of XSS to RCE which is dangerous for self-hosted users as well.
0
Attacker Value
Unknown
CVE-2022-25027
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
0