Lucene search

K

Forge Security Vulnerabilities

cve
cve

CVE-2022-43702

When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious...

7.8CVSS

7.7AI Score

0.001EPSS

2023-07-27 10:15 PM
23
cve
cve

CVE-2022-43703

An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended...

7.8CVSS

7.6AI Score

0.001EPSS

2023-07-27 10:15 PM
22
cve
cve

CVE-2022-43701

When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious...

7.8CVSS

7.5AI Score

0.001EPSS

2023-07-27 10:15 PM
27
cve
cve

CVE-2023-37976

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5...

7.1CVSS

6.2AI Score

0.001EPSS

2023-07-27 03:15 PM
17
cve
cve

CVE-2010-5242

Untrusted search path vulnerability in Sound Forge Pro 10.0b Build 474 allows local users to gain privileges via a Trojan horse MtxParhVegasPreview.dll file in the current working directory, as demonstrated by a directory that contains a .sfw file. NOTE: some of these details are obtained from...

6.7AI Score

0.0004EPSS

2022-10-03 04:21 PM
18
cve
cve

CVE-2011-1034

Cross-site scripting (XSS) vulnerability in the UI in IBM Rational Build Forge 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter to the fullcontrol program. NOTE: some of these details are obtained from third party...

5.8AI Score

0.002EPSS

2022-10-03 04:15 PM
19
cve
cve

CVE-2022-39221

McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program,.....

7.5CVSS

7.4AI Score

0.002EPSS

2022-09-21 12:15 AM
23
4
cve
cve

CVE-2022-24772

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a DigestInfo ASN.1 structure. This can allow padding bytes to be removed.....

7.5CVSS

7.3AI Score

0.001EPSS

2022-03-18 02:15 PM
139
2
cve
cve

CVE-2022-24773

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check DigestInfo for a proper ASN.1 structure. This can lead to successful verification with signatures that...

5.3CVSS

5.1AI Score

0.001EPSS

2022-03-18 02:15 PM
125
cve
cve

CVE-2022-24771

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses...

7.5CVSS

7.2AI Score

0.001EPSS

2022-03-18 02:15 PM
129
2
cve
cve

CVE-2022-0122

forge is vulnerable to URL Redirection to Untrusted...

6.1CVSS

6.2AI Score

0.001EPSS

2022-01-06 05:15 AM
45
cve
cve

CVE-2020-7720

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable...

9.8CVSS

7AI Score

0.002EPSS

2020-09-01 10:15 AM
70
cve
cve

CVE-2011-3391

IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security...

6.3AI Score

0.003EPSS

2011-09-08 06:55 PM
21
cve
cve

CVE-2011-1839

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser...

6.7AI Score

0.001EPSS

2011-04-28 06:55 PM
18
cve
cve

CVE-2008-2122

IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed...

7.5CVSS

7.3AI Score

0.019EPSS

2008-05-09 03:20 PM
22
cve
cve

CVE-2008-2088

SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to...

8.4AI Score

0.001EPSS

2008-05-06 03:20 PM
22
cve
cve

CVE-2006-3917

PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine...

8AI Score

0.056EPSS

2006-07-28 12:04 AM
28