Author: Angelo Barbosa

CVE-2023-24609 | Matrix SSL/Rambus TLS Toolkit Client Hello Pre-Shared Key Extension Parser tls13VerifyBinder/tls13TranscriptHashUpdate integer overflow

A vulnerability has been found in Matrix SSL and Rambus TLS Toolkit and classified as problematic. Affected by this vulnerability is the function tls13VerifyBinder/tls13TranscriptHashUpdate of the component Client Hello Pre-Shared Key Extension Parser. The manipulation leads to integer overflow. This vulnerability is known as CVE-2023-24609. Access to the local network is required for this attack. There is no exploit...

Read More

CVE-2023-51708 | Bentley eB System management Console Configuration Options information disclosure

A vulnerability, which was classified as problematic, was found in Bentley eB System management Console and ALIM For Transportation. Affected is an unknown function of the component Configuration Options Handler. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2023-51708. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-51704 | MediaWiki up to 1.35.13/1.39.5/1.40.1 on Special RightsLogFormatter.php cross site scripting

A vulnerability, which was classified as problematic, has been found in MediaWiki up to 1.35.13/1.39.5/1.40.1 on Special. This issue affects some unknown processing of the file includes/logging/RightsLogFormatter.php. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2023-51704. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-37519 | HCL Software BigFix Platform 9.5.x/10.0.x Download Status Report cross site scripting (KB0109376)

A vulnerability classified as problematic was found in HCL Software BigFix Platform 9.5.x/10.0.x. This vulnerability affects unknown code of the component Download Status Report. The manipulation leads to cross site scripting. This vulnerability was named CVE-2023-37519. The attack can be initiated remotely. There is no exploit...

Read More

CVE-2023-37520 | HCL HCL BigFix Platform 9.5.x/10.0.x/11.0.0 Gather Status Report cross site scripting (KB0109376)

A vulnerability classified as problematic has been found in HCL HCL BigFix Platform 9.5.x/10.0.x/11.0.0. This affects an unknown part of the component Gather Status Report. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2023-37520. It is possible to initiate the attack remotely. There is no exploit...

Read More