Show filters
43 Total Results
Displaying 1-10 of 43
Sort by:
Attacker Value
Unknown
CVE-2023-48795
Disclosure Date: December 18, 2023 (last updated April 30, 2024)
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0…
2
Attacker Value
Unknown
CVE-2020-1108
Disclosure Date: May 21, 2020 (last updated October 16, 2023)
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
1
Attacker Value
Unknown
CVE-2025-21171
Disclosure Date: January 14, 2025 (last updated February 06, 2025)
.NET Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-30045
Disclosure Date: May 14, 2024 (last updated January 12, 2025)
.NET and Visual Studio Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-21409
Disclosure Date: April 09, 2024 (last updated January 12, 2025)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-26190
Disclosure Date: March 12, 2024 (last updated January 12, 2025)
Microsoft QUIC Denial of Service Vulnerability
0
Attacker Value
Unknown
CVE-2024-21392
Disclosure Date: March 12, 2024 (last updated January 12, 2025)
.NET and Visual Studio Denial of Service Vulnerability
0
Attacker Value
Unknown
CVE-2024-0057
Disclosure Date: January 09, 2024 (last updated May 29, 2024)
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
0
Attacker Value
Unknown
CVE-2023-49213
Disclosure Date: November 23, 2023 (last updated November 30, 2023)
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
0
Attacker Value
Unknown
CVE-2023-36013
Disclosure Date: November 20, 2023 (last updated December 02, 2023)
PowerShell Information Disclosure Vulnerability
0