Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2022-33977
Disclosure Date: July 26, 2022 (last updated October 07, 2023)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
0
Attacker Value
Unknown
CVE-2022-31471
Disclosure Date: July 26, 2022 (last updated October 07, 2023)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
0
Attacker Value
Unknown
CVE-2020-17494
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Untangle Firewall NG before 16.0 uses MD5 for passwords.
0
Attacker Value
Unknown
CVE-2019-18648
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
0
Attacker Value
Unknown
CVE-2019-18647
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
0
Attacker Value
Unknown
CVE-2019-18649
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
0
Attacker Value
Unknown
CVE-2019-18646
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
0