Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Warp MEDIUM 6.8
CVE-2023-2754

The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS que…

Fix: 2023.7.160.0+
Fix from $1,600 2023-08-03
Warp HIGH 7.3
CVE-2023-1862

Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient …

Fix: after 2023.3.381.0
Fix from $1,950 2023-06-20
Cfnts HIGH 7.5
CVE-2023-3036

An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cfnts/commit/783490b913f05e508a…

Fix: 2023-06-01+
Fix from $1,950 2023-06-14
Lua Resty Json HIGH 7.5
CVE-2023-3040

A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bound…

Fix: 2023-05-05+
Fix from $1,950 2023-06-14
Workerd HIGH 8.1
CVE-2023-2512

Prior to version v1.20230419.0, the FormData API implementation was subject to an integer overflow. If a FormData instance contained more than 2^31 e…

Fix: 1.20230419.0+
Fix from $1,950 2023-05-12
Circl HIGH 8.2
CVE-2023-1732

When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In…

Fix: 1.3.3+
Fix from $1,950 2023-05-10
Warp HIGH 7.8
CVE-2023-0652

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 202…

Fix: 2023.3.381.0+
Fix from $1,950 2023-04-06
Warp HIGH 7.8
CVE-2023-1412

An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to…

Fix: 2023.3.381.0+
Fix from $1,950 2023-04-05
Cloudflared HIGH 7.8
CVE-2023-1314

A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no adminis…

Fix: 2023.3.1+
Fix from $1,950 2023-03-21
Warp HIGH 8.0
CVE-2022-4428

support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching …

Fix: after 2022.10.106.0
Fix from $1,950 2023-01-11
Warp MEDIUM 5.5
CVE-2022-4457

Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker coul…

Fix: 6.20+
Fix from $1,600 2023-01-11
Golz4 CRITICAL 9.8
CVE-2014-125026

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted us…

Fix: 2014-07-11+
Fix from $2,300 2022-12-27
Warp HIGH 8.8
CVE-2022-3512

Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trus…

Fix: 2022.8.857.0 / 2022.8.861.0+
Fix from $1,950 2022-10-28
Warp Mobile Client HIGH 8.5
CVE-2022-3337

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflar…

Fix: 6.15+
Fix from $1,950 2022-10-28
Warp Mobile Client HIGH 7.5
CVE-2022-3322

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to ins…

Fix: 6.14+
Fix from $1,950 2022-10-28
Warp Mobile Client HIGH 8.2
CVE-2022-3321

It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#…

Fix: 6.14+
Fix from $1,950 2022-10-28
Warp CRITICAL 9.8
CVE-2022-3320

It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this comman…

Fix: 2022.8.857.0 / 2022.8.861.0+
Fix from $2,300 2022-10-28
Octorpki HIGH 7.5
CVE-2022-3616

Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program…

Fix: 1.4.4+
Fix from $1,950 2022-10-28
Goflow HIGH 7.5
CVE-2022-2529

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packe…

Fix: 3.4.4+
Fix from $1,950 2022-09-30
Warp HIGH 7.8
CVE-2022-2225

By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust s…

Fix: 2022.5.227.0 / 2022.5.341.0+
Fix from $1,950 2022-07-26
Warp HIGH 7.8
CVE-2022-2145

Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the W…

Fix: 2022.5.309.0+
Fix from $1,950 2022-06-28
Warp HIGH 7.8
CVE-2022-2147

Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege e…

Fix: 2022.3.186.0+
Fix from $1,950 2022-06-23
Warp HIGH 7.8
CVE-2020-35152

Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative …

Fix: 1.2.2695.1+
Fix from $1,950 2021-02-03
Cloudflared HIGH 7.8
CVE-2020-24356

`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudf…

Fix: 2020.8.1+
Fix from $1,950 2020-10-02