CVE-2023-49930
- EPSS 0.48%
- Veröffentlicht 29.02.2024 01:41:40
- Zuletzt bearbeitet 28.03.2025 19:15:17
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
CVE-2023-45874
- EPSS 0.31%
- Veröffentlicht 29.02.2024 01:41:20
- Zuletzt bearbeitet 26.03.2025 21:15:20
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
CVE-2023-43769
- EPSS 0.15%
- Veröffentlicht 29.02.2024 01:41:09
- Zuletzt bearbeitet 08.04.2025 14:53:42
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.
CVE-2023-49338
- EPSS 0.38%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 23.04.2025 16:25:54
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.
CVE-2023-45873
- EPSS 0.39%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 23.04.2025 16:25:09
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.
CVE-2023-50782
- EPSS 0.71%
- Veröffentlicht 05.02.2024 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:37:18
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2024-0519
- EPSS 0.23%
- Veröffentlicht 16.01.2024 22:15:37
- Zuletzt bearbeitet 20.12.2024 19:01:11
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-36667
- EPSS 1%
- Veröffentlicht 08.11.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:10:16
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
CVE-2023-45875
- EPSS 0.36%
- Veröffentlicht 08.11.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:32
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.
CVE-2023-3079
- EPSS 0.62%
- Veröffentlicht 05.06.2023 22:15:12
- Zuletzt bearbeitet 05.02.2025 14:30:07
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)