Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2022-33977

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
Attacker Value
Unknown

CVE-2022-31471

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
Attacker Value
Unknown

CVE-2020-17494

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Untangle Firewall NG before 16.0 uses MD5 for passwords.
Attacker Value
Unknown

CVE-2019-18648

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
Attacker Value
Unknown

CVE-2019-18647

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
Attacker Value
Unknown

CVE-2019-18649

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
Attacker Value
Unknown

CVE-2019-18646

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.