Skip to content
Noroxi

Stormshield records

60 published records for vendor stormshield.

All records

60 records
  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    MediumCVSS 6.5No exploitEPSS 82%

    llhttp · llhttpJul 14, 2022

  • On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file p

    CriticalCVSS 9.8No exploitEPSS 29%

    clamav · clamavMar 1, 2023

  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    MediumCVSS 6.5No exploitEPSS 69%

    llhttp · llhttpJul 14, 2022

  • X.400 address type confusion in X.509 GeneralName

    HighCVSS 7.4No exploitEPSS 60%

    openssl · opensslFeb 8, 2023

  • zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    zlib · zlibAug 5, 2022

  • The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Caus

    CriticalCVSS 9.8No exploitEPSS 3%

    mpd project · mpdOct 6, 2020

  • Stormshield Endpoint Security before 2.1.2 allows remote code execution.

    CriticalCVSS 9.8No exploitEPSS 3%

    stormshield · endpoint securityDec 21, 2021

  • In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    stormshield · stormshield network securityJan 31, 2022

  • The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he

    MediumCVSS 6.5No exploitEPSS 44%

    llhttp · llhttpJul 14, 2022

  • The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not pub

    HighCVSS 7.5Proof of conceptEPSS 25%

    balasys · dheaterNov 11, 2021

  • CVE-2022-4450
    36Monitor

    Double free after calling PEM_read_bio_ex

    HighCVSS 7.5No exploitEPSS 20%

    openssl · opensslFeb 8, 2023

  • Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.

    HighCVSS 8.2No exploitEPSS 0%

    stormshield · stormshield network securityJul 4, 2019

  • CVE-2023-0215
    31Monitor

    Use-after-free following BIO_new_NDEF

    HighCVSS 7.5No exploitEPSS 4%

    openssl · opensslFeb 8, 2023

  • CVE-2020-7466
    31Monitor

    The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the

    HighCVSS 7.5No exploitEPSS 2%

    mpd project · mpdOct 6, 2020

  • CVE-2023-0216
    31Monitor

    Invalid pointer dereference in d2i_PKCS7 functions

    HighCVSS 7.5No exploitEPSS 2%

    openssl · opensslFeb 8, 2023

  • CVE-2023-0401
    31Monitor

    NULL dereference during PKCS7 data verification

    HighCVSS 7.5No exploitEPSS 2%

    openssl · opensslFeb 8, 2023

  • strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and i

    HighCVSS 7.5No exploitEPSS 2%

    strongswan · strongswanOct 31, 2022

  • Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

    HighCVSS 7.8No exploitEPSS 0%

    stormshield · ssl vpn clientAug 25, 2023

  • An issue was discovered in Stormshield SSL VPN Client before 3.2.0.

    HighCVSS 7.8No exploitEPSS 0%

    stormshield · ssl vpn clientAug 4, 2023

  • Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive c

    HighCVSS 7.5No exploitEPSS 1%

    stormshield · network securityMay 6, 2021

  • An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8.

    HighCVSS 7.5No exploitEPSS 1%

    stormshield · stormshield network securityMay 12, 2022

  • An issue was discovered in Stormshield SNS through 4.2.1.

    HighCVSS 7.5No exploitEPSS 1%

    stormshield · stormshield network securityJul 1, 2021

  • In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood

    HighCVSS 7.5No exploitEPSS 1%

    stormshield · stormshield network securityMar 15, 2022

  • An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8).

    HighCVSS 7.5No exploitEPSS 1%

    stormshield · network securityDec 29, 2021

  • Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lea

    HighCVSS 7.5No exploitEPSS 1%

    stormshield · stormshield network securityAug 24, 2022