VYPR

Communications Operations Monitor

by Oracle Corporation

CVEs (45)

  • CVE-2021-44790CriDec 20, 2021
    risk 0.74cvss 9.8epss 0.97

    A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP…

  • CVE-2018-11218CriJun 17, 2018
    risk 0.71cvss 9.8epss 0.59

    Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

  • CVE-2019-3822CriFeb 6, 2019
    risk 0.65cvss 9.8epss 0.13

    libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received…

  • CVE-2018-11219CriJun 17, 2018
    risk 0.64cvss 9.8epss 0.07

    An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.

  • CVE-2021-44224HigDec 20, 2021
    risk 0.60cvss 8.2epss 0.82

    A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server…

  • CVE-2020-11023MedKEVApr 29, 2020
    risk 0.60cvss 6.9epss 0.85

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This…

  • CVE-2019-5482CriSep 16, 2019
    risk 0.58cvss 9.8epss 0.18

    Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

  • CVE-2021-23017HigJun 1, 2021
    risk 0.57cvss 7.7epss 0.53

    A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

  • CVE-2019-5481CriSep 16, 2019
    risk 0.57cvss 9.8epss 0.07

    Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

  • CVE-2019-7164CriFeb 20, 2019
    risk 0.57cvss 9.8epss 0.04

    SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

  • CVE-2017-3730HigMay 4, 2017
    risk 0.56cvss 7.5epss 0.55

    In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

  • CVE-2019-7548HigFeb 6, 2019
    risk 0.51cvss 7.8epss 0.02

    SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

  • CVE-2021-32675HigOct 4, 2021
    risk 0.50cvss 7.5epss 0.16

    Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each…

  • CVE-2021-32628HigOct 4, 2021
    risk 0.50cvss 7.5epss 0.14

    Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves modifying the…

  • CVE-2021-32626HigOct 4, 2021
    risk 0.50cvss 7.5epss 0.16

    Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and…

  • CVE-2020-14147HigJun 15, 2020
    risk 0.50cvss 7.7epss 0.03

    An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox…

  • CVE-2021-41099HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability involves changing the default…

  • CVE-2021-32762HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.03

    Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vulnerability in the…

  • CVE-2021-32687HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remote code execution. The vulnerability…

  • CVE-2021-32627HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves changing the default proto-max-bulk-len and…

Page 1 of 3

VYPR — Vulnerability Intelligence