Show filters
391 Total Results
Displaying 91-100 of 391
Sort by:
Attacker Value
Unknown

CVE-2022-45195

Disclosure Date: November 12, 2022 (last updated February 24, 2025)
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.
Attacker Value
Unknown

CVE-2022-31772

Disclosure Date: November 11, 2022 (last updated February 24, 2025)
IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335.
Attacker Value
Unknown

CVE-2022-40230

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."
Attacker Value
Unknown

CVE-2022-35612

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field.
Attacker Value
Unknown

CVE-2022-35611

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.
Attacker Value
Unknown

CVE-2022-31008

Disclosure Date: October 06, 2022 (last updated February 24, 2025)
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.
Attacker Value
Unknown

CVE-2012-2201

Disclosure Date: September 29, 2022 (last updated December 22, 2024)
IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security configuration setup on a SVRCONN channel and flood the queue manager.
Attacker Value
Unknown

CVE-2022-1278

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Attacker Value
Unknown

CVE-2021-4178

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Attacker Value
Unknown

CVE-2021-4040

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.