Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2023-47712
Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
0
Attacker Value
Unknown
CVE-2023-47711
Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
0
Attacker Value
Unknown
CVE-2023-47709
Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
0
Attacker Value
Unknown
CVE-2023-42004
Disclosure Date: November 28, 2023 (last updated December 05, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
0
Attacker Value
Unknown
CVE-2022-43903
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
0
Attacker Value
Unknown
CVE-2022-43904
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
0
Attacker Value
Unknown
CVE-2023-30437
Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
0
Attacker Value
Unknown
CVE-2023-30436
Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292.
0
Attacker Value
Unknown
CVE-2023-30435
Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.
0