Lucene search

K

Rack Security Vulnerabilities

cve
cve

CVE-2024-35231

rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of service due to the fact that the user controlled data profiler_runs was not constrained to any limitation. This would lead to...

8.6CVSS

6.5AI Score

0.0004EPSS

2024-05-27 05:15 PM
27
cve
cve

CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issue. Accept and Forwarded headers are impacted. Ruby 3.2 has mitigations for this problem, so Rack applications using...

5.3CVSS

5.1AI Score

0.0004EPSS

2024-02-29 12:15 AM
112
cve
cve

CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the Rack::File middleware or the...

5.8CVSS

5.2AI Score

0.0004EPSS

2024-02-29 12:15 AM
110
cve
cve

CVE-2024-25126

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and...

5.3CVSS

5.1AI Score

0.0004EPSS

2024-02-29 12:15 AM
108
cve
cve

CVE-2023-20228

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input......

6.1CVSS

5.9AI Score

0.001EPSS

2023-08-16 09:15 PM
74
cve
cve

CVE-2023-28075

Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the...

6.9CVSS

6.5AI Score

0.0004EPSS

2023-08-16 08:15 PM
35
cve
cve

CVE-2023-28027

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
21
cve
cve

CVE-2023-28034

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
27
cve
cve

CVE-2023-28044

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
17
cve
cve

CVE-2023-28036

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
19
cve
cve

CVE-2023-28060

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
24
cve
cve

CVE-2023-28031

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
20
cve
cve

CVE-2023-28026

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
19
cve
cve

CVE-2023-28050

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
22
cve
cve

CVE-2023-28058

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
21
cve
cve

CVE-2023-25938

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 11:15 AM
21
cve
cve

CVE-2023-28059

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
16
cve
cve

CVE-2023-28052

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
17
cve
cve

CVE-2023-28054

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
13
cve
cve

CVE-2023-28035

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
12
cve
cve

CVE-2023-28039

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
14
cve
cve

CVE-2023-28041

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
12
cve
cve

CVE-2023-28061

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
10
cve
cve

CVE-2023-28040

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
11
cve
cve

CVE-2023-28056

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
12
cve
cve

CVE-2023-28042

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
13
cve
cve

CVE-2023-28028

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
11
cve
cve

CVE-2023-28030

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
11
cve
cve

CVE-2023-25937

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
19
cve
cve

CVE-2023-28029

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
16
cve
cve

CVE-2023-28032

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
11
cve
cve

CVE-2023-28033

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 10:15 AM
13
cve
cve

CVE-2023-25936

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI...

6.7CVSS

6.2AI Score

0.0004EPSS

2023-06-23 09:15 AM
11
cve
cve

CVE-2023-27530

A DoS vulnerability exists in...

7.5CVSS

7.3AI Score

0.001EPSS

2023-03-10 10:15 PM
156
cve
cve

CVE-2022-44571

There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of time, possibly...

7.5CVSS

7.2AI Score

0.001EPSS

2023-02-09 08:15 PM
105
cve
cve

CVE-2022-44572

A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of...

7.5CVSS

7.2AI Score

0.001EPSS

2023-02-09 08:15 PM
74
cve
cve

CVE-2022-44570

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with....

7.5CVSS

7.2AI Score

0.001EPSS

2023-02-09 08:15 PM
78
cve
cve

CVE-2022-34398

Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the...

7.5CVSS

7.1AI Score

0.0004EPSS

2023-02-01 06:15 AM
38
cve
cve

CVE-2022-30123

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of...

10CVSS

9.3AI Score

0.005EPSS

2022-12-05 10:15 PM
213
2
cve
cve

CVE-2022-30122

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of...

7.5CVSS

8.1AI Score

0.001EPSS

2022-12-05 10:15 PM
189
2
cve
cve

CVE-2022-32489

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in...

8.2CVSS

7.8AI Score

0.0004EPSS

2022-10-12 08:15 PM
28
4
cve
cve

CVE-2022-32485

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-10-12 08:15 PM
25
4
cve
cve

CVE-2022-32484

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI...

5.6CVSS

4.5AI Score

0.0004EPSS

2022-10-12 08:15 PM
20
4
cve
cve

CVE-2022-32488

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in...

8.2CVSS

7.8AI Score

0.0004EPSS

2022-10-12 08:15 PM
21
4
cve
cve

CVE-2022-32487

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-10-12 08:15 PM
22
4
cve
cve

CVE-2022-32491

Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during...

7.8CVSS

7.4AI Score

0.0004EPSS

2022-10-12 08:15 PM
20
4
cve
cve

CVE-2022-32493

Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in...

7.8CVSS

7.9AI Score

0.0004EPSS

2022-10-12 08:15 PM
24
4
cve
cve

CVE-2022-32483

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI...

5.6CVSS

4.5AI Score

0.0004EPSS

2022-10-12 08:15 PM
30
4
cve
cve

CVE-2009-1798

Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE:...

6AI Score

0.004EPSS

2022-10-03 04:23 PM
46
cve
cve

CVE-2009-1797

Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to hijack the authentication of (1) administrator or (2) device.....

7.8AI Score

0.001EPSS

2022-10-03 04:23 PM
74
Total number of security vulnerabilities86