VYPR

Vendor CVEs

Broadcom Corporation

All CVEs

798 total · sorted by risk
  • CVE-2026-41721MedJun 10, 2026
    risk 0.38cvss 5.9epss 0.00

    Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTTP request that causes the…

  • CVE-2025-22245MedJun 4, 2025
    risk 0.38cvss 5.9epss 0.00

    VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.

  • CVE-2024-29954MedJun 26, 2024
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail.…

  • CVE-2023-23956MedMay 30, 2023
    risk 0.38cvss 5.4epss 0.03

    A user can supply malicious HTML and JavaScript code that will be executed in the client browser

  • CVE-2023-27537MedMar 30, 2023
    risk 0.38cvss 5.9epss 0.02

    A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing…

  • CVE-2020-3993MedOct 20, 2020
    risk 0.38cvss 5.9epss 0.01

    VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the…

  • CVE-2019-18376MedApr 10, 2020
    risk 0.38cvss 5.9epss 0.01

    A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

  • CVE-2017-18268MedMay 17, 2018
    risk 0.38cvss 5.9epss 0.02

    Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the…

  • CVE-2026-57216MedJul 10, 2026
    risk 0.37cvss 6.8epss 0.01

    RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol…

  • CVE-2022-43937MedNov 21, 2024
    risk 0.37cvss 5.7epss 0.00

    Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before 2.3.0 and 2.2.2a

  • CVE-2024-29964MedApr 19, 2024
    risk 0.37cvss 5.7epss 0.01

    Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.

  • CVE-2024-29951MedApr 17, 2024
    risk 0.37cvss 5.7epss 0.00

    Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.

  • CVE-2023-31423MedAug 31, 2023
    risk 0.37cvss 5.7epss 0.00

    Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected…

  • CVE-2025-58379MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user.

  • CVE-2025-50200MedJun 19, 2025
    risk 0.36cvss 5.5epss 0.00

    RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including…

  • CVE-2024-10404MedFeb 14, 2025
    risk 0.36cvss 5.5epss 0.00

    CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges…

  • CVE-2024-29962MedApr 19, 2024
    risk 0.36cvss 5.5epss 0.00

    Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.

  • CVE-2024-29952MedApr 17, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

  • CVE-2023-4256MedDec 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local…

  • CVE-2023-4333MedAug 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server

  • CVE-2023-4328MedAug 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows

  • CVE-2023-4327MedAug 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux

  • CVE-2023-31431MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service.

  • CVE-2023-31430MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service.

  • CVE-2023-31428MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.00

    Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files under user's home directory using grep.

  • CVE-2023-31429MedAug 1, 2023
    risk 0.36cvss 5.5epss 0.00

    Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgdisable and supportshowcfgenable commands…

  • CVE-2023-27538MedMar 30, 2023
    risk 0.36cvss 5.5epss 0.01

    An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse…

  • CVE-2022-33187MedDec 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.

  • CVE-2022-33181MedOct 25, 2022
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”.

  • CVE-2022-33180MedOct 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.

  • CVE-2021-27798MedAug 5, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described…

  • CVE-2022-28161MedMay 9, 2022
    risk 0.36cvss 5.5epss 0.00

    An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local attacker to view sensitive information such as ssh passwords in filetansfer.log in debug mode. To exploit this vulnerability, the…

  • CVE-2022-27939MedMar 26, 2022
    risk 0.36cvss 5.5epss 0.01

    tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.

  • CVE-2022-25484MedMar 22, 2022
    risk 0.36cvss 5.5epss 0.01

    tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.

  • CVE-2021-45387MedFeb 11, 2022
    risk 0.36cvss 5.5epss 0.01

    tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.

  • CVE-2021-45386MedFeb 11, 2022
    risk 0.36cvss 5.5epss 0.01

    tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c

  • CVE-2020-23273MedSep 22, 2021
    risk 0.36cvss 5.5epss 0.01

    Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.

  • CVE-2020-18976MedAug 25, 2021
    risk 0.36cvss 5.5epss 0.01

    Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381.

  • CVE-2021-26314MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.

  • CVE-2021-26313MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.

  • CVE-2020-35507MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application…

  • CVE-2020-35496MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw…

  • CVE-2020-35495MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions…

  • CVE-2020-35493MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to…

  • CVE-2020-0019MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID:…

  • CVE-2020-15372MedSep 25, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or…

  • CVE-2019-16210MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.

  • CVE-2019-16206MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.

  • CVE-2018-6433MedNov 8, 2018
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to bypass the export file access restrictions and initiate a file copy from the source to a remote system.

  • CVE-2018-18407MedOct 17, 2018
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4() in incremental_checksum.h, causing a denial of service.

Page 10 of 16