VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2021-32923Medium· 6.5
5y ago

vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)

A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 1.4%via CSAF
CVE-2021-33194High· 7.5
5y ago

golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)

A flaw was found in golang. An attacker can craft an input to ParseFragment within parse.go that would cause it to enter an infinite loop and never return. The greatest threat to the system is of availability.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 7.5%via CSAF
CVE-2021-1532Medium· 6.5
5y ago

Cisco Telepresence CE and RoomOS Software Arbitrary File Read Vulnerability

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating syste…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 1.4%via CSAF
CVE-2021-29425Medium· 4.8PoC
5y ago

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…

▾ Twilightapache · commons_ioEPSS 9.9%via NVD
CVE-2021-1371Medium· 6.6
5y ago

Cisco SD-WAN Software Improper Privilege Management Vulnerability

A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.25%via CSAF
CVE-2021-1449Medium· 6.7
5y ago

Cisco Aironet Access Points Privilege Escalation Vulnerability

A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code th…

▾ SunlitCisco · Cisco Aironet Access Point SoftwareEPSS 0.27%via CSAF
CVE-2021-1437High· 7.5
5y ago

Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability (CVE-2021-1437)

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to a…

▾ TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 1.5%via CSAF
CVE-2021-1273High· 7.5
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ TwilightCisco · Cisco SD-WAN vContainerEPSS 1.4%via CSAF
CVE-2021-1279Medium· 5.3
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ SunlitCisco · Cisco Catalyst SD-WAN ManagerEPSS 1.4%via CSAF
CVE-2021-1278Medium· 5.5
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ SunlitCisco · Cisco 4000 Series Integrated Services RoutersEPSS 1.7%via CSAF
CVE-2021-1274High· 7.5
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ TwilightCisco · Cisco 4000 Series Integrated Services RoutersEPSS 1.9%via CSAF
CVE-2021-1241High· 8.6
5y ago

Cisco SD-WAN vEdge Routers Denial of Service Vulnerability

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ TwilightCisco · Cisco SD-WAN vEdge CloudEPSS 1.4%via CSAF
CVE-2020-26068Medium· 5.5
5y ago

Cisco Telepresence CE Software and RoomOS Software Unauthorized Configuration Change Vulnerability

A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient a…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.73%via CSAF
CVE-2020-26086Medium· 4.3
5y ago

Cisco TelePresence Collaboration Endpoint Software Information Disclosure Vulnerability (CVE-2020-26086)

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability i…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.85%via CSAF
CVE-2020-14040High· 7.5
6y ago

golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vuln…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.6EPSS 1.8%via CSAF
CVE-2020-6851High· 7.5
6y ago

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

▾ Twilightuclouvain · openjpegEPSS 5.2%via NVD
CVE-2017-6664Medium· 6.5
9y ago

Cisco IOS XE Software Autonomic Networking Infrastructure Certificate Revocation Vulnerability (CVE-2017-6664)

A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the auto…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.92%via CSAF
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

▾ Sunlitopenstack · glanceEPSS 2.1%via NVD
CVEs tagged “csaf” — page 105 · VulnSea