CVE-2025-2170
- EPSS 0.02%
- Published 30.04.2025 18:46:34
- Last modified 14.05.2025 17:15:47
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to a...
CVE-2024-45317
- EPSS 0.09%
- Published 11.10.2024 13:15:16
- Last modified 22.03.2025 15:15:37
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
CVE-2023-0126
- EPSS 92.86%
- Published 19.01.2023 20:15:10
- Last modified 03.04.2025 20:15:19
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.
CVE-2022-0847
- EPSS 83.71%
- Published 10.03.2022 17:44:57
- Last modified 30.07.2025 19:10:07
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user co...
CVE-2021-33909
- EPSS 3.54%
- Published 20.07.2021 19:15:09
- Last modified 21.11.2024 06:09:45
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
CVE-2020-5129
- EPSS 0.51%
- Published 26.03.2020 13:15:13
- Last modified 21.11.2024 05:33:35
A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Denial of Service. This vulnerability affected SMA1000 Version 12.1.0-06411 and earlier.