Search Results (2806 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-38342 1 Safe 1 Fme Server 2024-11-21 8.5 High
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks.
CVE-2022-37189 1 Ddmal 1 Mei2volpiano 2024-11-21 7.5 High
DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.
CVE-2022-36773 2 Ibm, Netapp 2 Cognos Analytics, Oncommand Insight 2024-11-21 8.1 High
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
CVE-2022-36522 1 Mikrotik 1 Routeros 2024-11-21 6.5 Medium
Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
CVE-2022-36440 4 Debian, Fedoraproject, Frrouting and 1 more 4 Debian Linux, Fedora, Frrouting and 1 more 2024-11-21 7.5 High
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
CVE-2022-35741 1 Apache 1 Cloudstack 2024-11-21 9.8 Critical
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the vulnerability. When the SAML 2.0 plugin is enabled in affected versions of Apache CloudStack could potentially allow the exploitation of XXE vulnerabilities. The SAML 2.0 messages constructed during the authentication flow in Apache CloudStack are XML-based and the XML data is parsed by various standard libraries that are now understood to be vulnerable to XXE injection attacks such as arbitrary file reading, possible denial of service, server-side request forgery (SSRF) on the CloudStack management server.
CVE-2022-35728 1 F5 12 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 9 more 2024-11-21 8.1 High
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2022-35205 1 Gnu 1 Binutils 2024-11-21 5.5 Medium
An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.
CVE-2022-35168 1 Sap 1 Business One 2024-11-21 7.5 High
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.
CVE-2022-34967 1 Monetdb 1 Monetdb 2024-11-21 7.5 High
The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.
CVE-2022-34832 1 Vermeg 1 Agile Reporter 2024-11-21 6.5 Medium
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
CVE-2022-34793 1 Jenkins 1 Recipe 2024-11-21 8.8 High
Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-34624 1 Mealie 1 Mealie 2024-11-21 5.9 Medium
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
CVE-2022-34144 1 Qualcomm 136 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 133 more 2024-11-21 7.5 High
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
CVE-2022-34001 1 Unit4 1 Enterprise Resource Planning 2024-11-21 6.5 Medium
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
CVE-2022-34000 1 Libjxl Project 1 Libjxl 2024-11-21 6.5 Medium
libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.
CVE-2022-33272 1 Qualcomm 98 Ar8035, Ar8035 Firmware, Qca6390 and 95 more 2024-11-21 7.5 High
Transient DOS in modem due to reachable assertion.
CVE-2022-33254 1 Qualcomm 128 Aqt1000, Aqt1000 Firmware, Ar8035 and 125 more 2024-11-21 7.5 High
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
CVE-2022-33251 1 Qualcomm 148 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 145 more 2024-11-21 7.5 High
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
CVE-2022-33250 1 Qualcomm 130 Ar8035, Ar8035 Firmware, Qca6390 and 127 more 2024-11-21 7.5 High
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.