Show filters
165 Total Results
Displaying 1-10 of 165
Sort by:
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2023-50950
Disclosure Date: January 17, 2024 (last updated January 25, 2024)
IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.
0
Attacker Value
Unknown
CVE-2023-47146
Disclosure Date: December 19, 2023 (last updated December 28, 2023)
IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.
0
Attacker Value
Unknown
CVE-2023-43057
Disclosure Date: November 11, 2023 (last updated November 17, 2023)
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267484.
0
Attacker Value
Unknown
CVE-2023-43041
Disclosure Date: October 29, 2023 (last updated November 08, 2023)
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. This vulnerability is due to an incomplete fix for CVE-2022-34352. IBM X-Force ID: 266808.
0
Attacker Value
Unknown
CVE-2023-40367
Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 263376.
0
Attacker Value
Unknown
CVE-2023-30994
Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138
0
Attacker Value
Unknown
CVE-2023-26276
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147.
0
Attacker Value
Unknown
CVE-2023-26274
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144.
0
Attacker Value
Unknown
CVE-2023-26273
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134.
0