VulnSea

universal_forwarder vulnerabilities

CVEs whose affected-version data names the universal_forwarder package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2022-36227Critical· 9.8
3y ago

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites…

▾ Midnightlibarchive · libarchiveEPSS 2.4%via NVD
CVE-2022-30115Medium· 4.3
4y ago

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing…

▾ Sunlithaxx · curlEPSS 1.3%via NVD
CVE-2022-27778High· 8.1
4y ago

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

▾ Twilighthaxx · curlEPSS 3.8%via NVD
CVE-2021-22901High· 8.1
5y ago

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstance…

▾ Twilighthaxx · curlEPSS 60%via NVD
CVE-2021-3520Critical· 9.8
5y ago

There's a flaw in lz4

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/o…

▾ Midnightlz4_project · lz4EPSS 3.2%via NVD
CVE-2019-20838High· 7.5
6y ago

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

▾ Twilightpcre · pcreEPSS 2.8%via NVD
CVE-2020-14155Medium· 5.3
6y ago

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

▾ Sunlitpcre · pcreEPSS 4.2%via NVD
universal_forwarder vulnerabilities (CVEs) · VulnSea