Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Password Manager CRITICAL 9.8
CVE-2023-48654

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login sc…

Fix: 5.13.1+
Fix from $2,300 2023-12-25
Password Manager HIGH 8.8
CVE-2023-51772

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login sc…

Fix: 5.13.1+
Fix from $1,950 2023-12-25
Password Manager MEDIUM 6.8
CVE-2023-4003

One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM th…

Fix: 5.11.2 / 5.12.2+
Fix from $1,600 2023-09-27
Syslog Ng HIGH 7.5
CVE-2022-38725

An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted…

Fix: 3.38.1 / 6.0.5+
Fix from $1,950 2023-01-23
Password Manager MEDIUM 5.3
CVE-2020-7962

An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to…

Mitigation only
Fix from $1,600 2020-11-13
Syslog Ng HIGH 7.8
CVE-2020-8019

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise…

Fix: 2.0.9-27.34.40.5.1 / 3.6.4-12.8.1+
Fix from $1,950 2020-06-29
Cloud Access Manager MEDIUM 6.5
CVE-2019-13497

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

Fix: 8.1.4+
Fix from $1,600 2019-11-04
Cloud Access Manager HIGH 8.1
CVE-2019-13496

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender produc…

Fix: 8.1.4+
Fix from $1,950 2019-11-04
Cloud Access Manager HIGH 7.4
CVE-2019-13498

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This is…

No fix yet
Fix from $1,950 2019-07-29
Syslog Ng MEDIUM 6.9
CVE-2011-0343

Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng …

Patch available
Fix from $1,600 2011-01-28
Syslog Ng HIGH 9.3
CVE-2008-5110

syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when …

Fix: after 2.0.9
Fix from $1,950 2008-11-17
Syslog Ng HIGH 7.5
CVE-2002-1200EPSS 6%

Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer…

Patch available
Fix from $1,950 2002-10-28