Show filters
54 Total Results
Displaying 1-10 of 54
Sort by:
Attacker Value
Unknown
CVE-2024-0519
Disclosure Date: January 16, 2024 (last updated August 15, 2024)
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
3
Attacker Value
Unknown
CVE-2023-3079
Disclosure Date: June 05, 2023 (last updated February 06, 2025)
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1
Attacker Value
Unknown
CVE-2024-25673
Disclosure Date: September 19, 2024 (last updated September 25, 2024)
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
0
Attacker Value
Unknown
CVE-2024-37034
Disclosure Date: July 26, 2024 (last updated September 20, 2024)
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
0
Attacker Value
Unknown
CVE-2024-23302
Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
0
Attacker Value
Unknown
CVE-2023-49930
Disclosure Date: February 29, 2024 (last updated February 15, 2025)
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
0
Attacker Value
Unknown
CVE-2023-45874
Disclosure Date: February 29, 2024 (last updated February 15, 2025)
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
0
Attacker Value
Unknown
CVE-2023-50782
Disclosure Date: February 05, 2024 (last updated September 06, 2024)
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
0
Attacker Value
Unknown
CVE-2023-36667
Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
0
Attacker Value
Unknown
CVE-2023-45875
Disclosure Date: November 08, 2023 (last updated November 17, 2023)
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.
0