Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2023-44487
Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1
Attacker Value
Unknown
CVE-2024-7596
Disclosure Date: February 05, 2025 (last updated February 07, 2025)
Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
0
Attacker Value
Unknown
CVE-2024-7595
Disclosure Date: February 05, 2025 (last updated February 07, 2025)
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
0
Attacker Value
Unknown
CVE-2025-23019
Disclosure Date: January 14, 2025 (last updated January 30, 2025)
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.
0
Attacker Value
Unknown
CVE-2025-23018
Disclosure Date: January 14, 2025 (last updated January 30, 2025)
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
0
Attacker Value
Unknown
CVE-2024-51784
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VietFriend team FriendStore for WooCommerce allows Reflected XSS.This issue affects FriendStore for WooCommerce: from n/a through 1.4.2.
0
Attacker Value
Unknown
CVE-2021-27861
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)
0
Attacker Value
Unknown
CVE-2021-27854
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.
0
Attacker Value
Unknown
CVE-2021-27853
Disclosure Date: September 27, 2022 (last updated December 22, 2024)
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
0
Attacker Value
Unknown
CVE-2021-27862
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).
0