Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-23759

Disclosure Date: May 18, 2023 (last updated October 08, 2023)
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
Attacker Value
Unknown

CVE-2019-11924

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
0
Attacker Value
Unknown

CVE-2019-3560

Disclosure Date: April 29, 2019 (last updated November 08, 2023)
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
Attacker Value
Unknown

CVE-2008-3378

Disclosure Date: July 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
0
Attacker Value
Unknown

CVE-2007-1678

Disclosure Date: March 26, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler.
0