7.5

CVSS3.1

CVE-2024-34363 - Envoy can crash due to uncaught nlohmann JSON exception

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:18 a.m.

5.9

CVSS3.1

CVE-2024-32975 - Envoy crashes in QuicheDataReader::PeekVarInt62Length()

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` implementation.

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:16 a.m.

5.9

CVSS3.1

CVE-2023-1419 - Debezium: script injection via connector parameter

A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data.

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2024-34364 - Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:18 a.m.

5.9

CVSS3.1

CVE-2024-23326 - Envoy incorrectly accepts HTTP 200 response for entering upgrade mode

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching prot…

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 8:57 a.m.

9.8

CVSS3.1

CVE-2024-24790 - Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Feb. 13, 2025, 5:40 p.m.

5.9

CVSS3.1

CVE-2024-32974 - Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused by QUICHE continuing push request headers after `StopReading()` being called on the stream. As after `Sto…

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:16 a.m.

5.3

CVSS3.1

CVE-2024-24789 - Mishandling of corrupt central directory record in archive/zip

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects fi…

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Feb. 13, 2025, 5:40 p.m.

5.4

CVSS3.1

CVE-2024-28103 - Action Pack is missing security headers on non-HTML responses

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

πŸ“… Published: June 4, 2024, midnight πŸ”„ Last Modified: Dec. 6, 2024, 2:15 p.m.

4.3

CVSS3.1

CVE-2023-28492 - WordPress Calendar Event Multi View plugin <= 1.4.10 - Missing Authorization Leading To Feedback Su…

Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.

πŸ“… Published: June 3, 2024, 10:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9599 of 34,919
Β« previous page Β» next page
Filters