CVE-2021-31851
- EPSS 0.78%
- Published 23.11.2021 20:15:10
- Last modified 21.11.2024 06:06:21
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodif...
CVE-2021-31852
- EPSS 0.91%
- Published 23.11.2021 20:15:10
- Last modified 21.11.2024 06:06:21
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into th...
CVE-2020-15719
- EPSS 0.14%
- Published 14.07.2020 14:15:17
- Last modified 21.11.2024 05:06:05
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openl...
CVE-2019-16168
- EPSS 0.84%
- Published 09.09.2019 17:15:13
- Last modified 21.11.2024 04:30:11
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
CVE-2019-13057
- EPSS 1.14%
- Published 26.07.2019 13:15:12
- Last modified 21.11.2024 04:24:07
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not pro...
CVE-2017-17740
- EPSS 2.84%
- Published 18.12.2017 06:29:00
- Last modified 20.04.2025 01:37:25
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd...
CVE-2017-9287
- EPSS 38.97%
- Published 29.05.2017 16:29:00
- Last modified 20.04.2025 01:37:25
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
CVE-2016-4472
- EPSS 1.68%
- Published 30.06.2016 17:59:04
- Last modified 12.04.2025 10:46:40
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists ...
CVE-2016-0718
- EPSS 1.5%
- Published 26.05.2016 16:59:00
- Last modified 12.04.2025 10:46:40
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.