Show filters
897 Total Results
Displaying 311-320 of 897
Sort by:
Attacker Value
Unknown
CVE-2023-5330
Disclosure Date: October 09, 2023 (last updated February 25, 2025)
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
0
Attacker Value
Unknown
CVE-2023-5160
Disclosure Date: October 02, 2023 (last updated February 25, 2025)
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
0
Attacker Value
Unknown
CVE-2023-5196
Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
0
Attacker Value
Unknown
CVE-2023-5195
Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
0
Attacker Value
Unknown
CVE-2023-5194
Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
0
Attacker Value
Unknown
CVE-2023-5193
Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
0
Attacker Value
Unknown
CVE-2023-5159
Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.
0
Attacker Value
Unknown
CVE-2023-41109
Disclosure Date: August 28, 2023 (last updated February 25, 2025)
SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.
0
Attacker Value
Unknown
CVE-2023-4478
Disclosure Date: August 25, 2023 (last updated February 25, 2025)
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
0
Attacker Value
Unknown
CVE-2020-28840
Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
0