Lucene search

K

Health Insurance Web Service Component Security Vulnerabilities

cve
cve

CVE-2021-45918

NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authent...

7.5CVSS

7.6AI Score

0.002EPSS

2022-06-20 06:15 AM
38
4
cve
cve

CVE-2022-35217

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disr...

7.8CVSS

8AI Score

0.0004EPSS

2022-08-02 04:15 PM
41
2
cve
cve

CVE-2022-35218

The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

5.5CVSS

5.7AI Score

0.0004EPSS

2022-08-02 04:15 PM
30
cve
cve

CVE-2022-35219

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

5.5CVSS

5.7AI Score

0.0004EPSS

2022-08-02 04:15 PM
36
2