Unknown · CVSS Not scored
In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so there was the possibility of rare (in general usage) spurious calculations for elliptic curve scalar multiplications. Such errors would have been detected with high probability by the output validation for our scalar multipliers.
Published Jun 4, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
Published Jun 1, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
Published Jun 4, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well.
Published Jun 4, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.
Published Jun 4, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
Published Jun 19, 2020 · Updated Aug 6, 2024
Medium · CVSS 4
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in mback2k mh_httpbl Extension up to 1.1.7 on TYPO3. This affects the function stopOutput of the file class.tx_mhhttpbl.php. The manipulation of the argument $_SERVER['REMOTE_ADDR'] leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.1.8 is able to address this issue. The patch is named a754bf306a433a8c18b55e25595593e8f19b9463. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230391. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published Jun 1, 2023 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.
Published Jun 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
Published Jun 29, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that "the underlying problem is non-trivial to handle.
Published Jun 21, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
Published Jun 4, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
Published Jun 1, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges.
Published Jun 15, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Published Jun 16, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
Published Jun 13, 2017 · Updated Aug 6, 2024