Show filters
43 Total Results
Displaying 1-10 of 43
Sort by:
Attacker Value
Unknown

CVE-2023-48795

Disclosure Date: December 18, 2023 (last updated April 30, 2024)
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0…
Attacker Value
Unknown

CVE-2020-1108

Disclosure Date: May 21, 2020 (last updated October 16, 2023)
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Attacker Value
Unknown

CVE-2025-21171

Disclosure Date: January 14, 2025 (last updated February 06, 2025)
.NET Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2024-30045

Disclosure Date: May 14, 2024 (last updated January 12, 2025)
.NET and Visual Studio Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2024-21409

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2024-26190

Disclosure Date: March 12, 2024 (last updated January 12, 2025)
Microsoft QUIC Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2024-21392

Disclosure Date: March 12, 2024 (last updated January 12, 2025)
.NET and Visual Studio Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2024-0057

Disclosure Date: January 09, 2024 (last updated May 29, 2024)
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-49213

Disclosure Date: November 23, 2023 (last updated November 30, 2023)
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
Attacker Value
Unknown

CVE-2023-36013

Disclosure Date: November 20, 2023 (last updated December 02, 2023)
PowerShell Information Disclosure Vulnerability