CVE-2023-37536
- EPSS 1%
- Veröffentlicht 11.10.2023 07:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:53
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
CVE-2022-42453
- EPSS 0.1%
- Veröffentlicht 19.12.2022 11:15:10
- Zuletzt bearbeitet 17.04.2025 15:15:47
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
CVE-2022-38659
- EPSS 0.02%
- Veröffentlicht 19.12.2022 11:15:10
- Zuletzt bearbeitet 17.04.2025 16:15:24
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
CVE-2022-27545
- EPSS 0.27%
- Veröffentlicht 19.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:56
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2022-27544
- EPSS 0.19%
- Veröffentlicht 19.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:56
BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2021-27767
- EPSS 0.04%
- Veröffentlicht 06.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:58:31
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version...
CVE-2021-27766
- EPSS 0.04%
- Veröffentlicht 06.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:58:31
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version ...
CVE-2021-27765
- EPSS 0.05%
- Veröffentlicht 06.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:58:31
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield vers...
CVE-2021-27762
- EPSS 0.27%
- Veröffentlicht 06.05.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:31
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
CVE-2021-27761
- EPSS 0.12%
- Veröffentlicht 06.05.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:31
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks