VYPR
Vendor

Oneidentity

Products
6
CVEs
16
Across products
19
Status
Private

Products

6

Recent CVEs

16
  • CVE-2023-48654CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape…

  • CVE-2023-51772HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape…

  • CVE-2019-13496HigNov 4, 2019
    risk 0.53cvss 8.1epss 0.01

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

  • CVE-2020-8019HigJun 29, 2020
    risk 0.50cvss 7.7epss 0.01

    A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux…

  • CVE-2023-4003HigSep 27, 2023
    risk 0.49cvss 7.6epss 0.00

    One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.

  • CVE-2022-38725HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.02

    An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0…

  • CVE-2019-13498HigJul 29, 2019
    risk 0.48cvss 7.4epss 0.01

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

  • CVE-2019-13497MedNov 4, 2019
    risk 0.42cvss 6.5epss 0.01

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

  • CVE-2020-7962MedNov 13, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password.…

  • CVE-2024-47619HigMay 7, 2025
    risk 0.00cvss 7.5epss 0.00

    syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided /…

  • CVE-2011-1951Jul 11, 2011
    risk 0.00cvss epss 0.02

    lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.

  • CVE-2011-0343Jan 28, 2011
    risk 0.00cvss epss 0.00

    Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to…

  • CVE-2008-5110Nov 17, 2008
    risk 0.00cvss epss 0.02

    syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.

  • CVE-2007-6437Dec 19, 2007
    risk 0.00cvss epss 0.03

    Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference.

  • CVE-2002-1200Oct 28, 2002
    risk 0.00cvss epss 0.06

    Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and…

  • CVE-2000-1165Jan 9, 2001
    risk 0.00cvss epss 0.02

    Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.