Show filters
54 Total Results
Displaying 1-10 of 54
Sort by:
Attacker Value
Unknown

CVE-2024-0519

Disclosure Date: January 16, 2024 (last updated August 15, 2024)
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2023-3079

Disclosure Date: June 05, 2023 (last updated February 06, 2025)
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2024-25673

Disclosure Date: September 19, 2024 (last updated September 25, 2024)
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
Attacker Value
Unknown

CVE-2024-37034

Disclosure Date: July 26, 2024 (last updated September 20, 2024)
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
Attacker Value
Unknown

CVE-2024-23302

Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
Attacker Value
Unknown

CVE-2023-49930

Disclosure Date: February 29, 2024 (last updated February 15, 2025)
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
Attacker Value
Unknown

CVE-2023-45874

Disclosure Date: February 29, 2024 (last updated February 15, 2025)
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
Attacker Value
Unknown

CVE-2023-50782

Disclosure Date: February 05, 2024 (last updated September 06, 2024)
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Attacker Value
Unknown

CVE-2023-36667

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
Attacker Value
Unknown

CVE-2023-45875

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.