CVE-2024-21985
- EPSS 0.17%
- Veröffentlicht 26.01.2024 16:15:22
- Zuletzt bearbeitet 21.11.2024 08:55:19
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond t...
CVE-2023-27314
- EPSS 0.6%
- Veröffentlicht 12.10.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:52:37
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service.
CVE-2023-36054
- EPSS 0.65%
- Veröffentlicht 07.08.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:15
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate t...
CVE-2023-3107
- EPSS 0.21%
- Veröffentlicht 01.08.2023 23:15:30
- Zuletzt bearbeitet 09.07.2025 14:15:26
A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
CVE-2023-2953
- EPSS 1.11%
- Veröffentlicht 30.05.2023 22:15:10
- Zuletzt bearbeitet 10.01.2025 22:15:23
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
CVE-2023-28321
- EPSS 0.3%
- Veröffentlicht 26.05.2023 21:15:16
- Zuletzt bearbeitet 15.01.2025 16:15:26
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function...
CVE-2023-28322
- EPSS 0.5%
- Veröffentlicht 26.05.2023 21:15:16
- Zuletzt bearbeitet 21.11.2024 07:54:50
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if ...
CVE-2023-28320
- EPSS 0.64%
- Veröffentlicht 26.05.2023 21:15:15
- Zuletzt bearbeitet 15.01.2025 16:15:25
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow...
CVE-2023-28319
- EPSS 0.32%
- Veröffentlicht 26.05.2023 21:15:10
- Zuletzt bearbeitet 15.01.2025 16:15:25
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error m...
CVE-2023-27533
- EPSS 0.14%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:06
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing a...