Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2025-25069

Disclosure Date: February 07, 2025 (last updated February 08, 2025)
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is similiar to CVE-2016-10517 in Redis. This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0. Users are recommended to upgrade to version 2.11.1, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-44076

Disclosure Date: August 19, 2024 (last updated August 22, 2024)
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
Attacker Value
Unknown

CVE-2023-48910

Disclosure Date: December 04, 2023 (last updated December 08, 2023)
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Attacker Value
Unknown

CVE-2019-12440

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
0
Attacker Value
Unknown

CVE-2011-4606

Disclosure Date: December 15, 2011 (last updated October 04, 2023)
Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory.
0
Attacker Value
Unknown

CVE-2006-3693

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call.
0