5 results (0.001 seconds)

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

30 Jul 2024 — A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender. • https://kb.cert.org/vuls/id/244112 •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

21 Dec 2022 — A vulnerability, which was classified as problematic, has been found in sileht bird-lg. This issue affects some unknown processing of the file templates/layout.html. The manipulation of the argument request_args leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ef6b32c527478fefe7a4436e10b96ee28ed5b308. • https://github.com/sileht/bird-lg/commit/ef6b32c527478fefe7a4436e10b96ee28ed5b308 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

08 Jun 2018 — BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc. BIRD Internet Routing Daemon en versiones anteriores a la 1.6.4 permite que usuarios locales provoquen una denegación de servicio (consumo de pila y cierre inesperado del demonio) mediante expresiones BGP mask en birdc. • http://bird.network.cz • CWE-400: Uncontrolled Resource Consumption •

CVSS: 9.6EPSS: 0%CPEs: 1EXPL: 4

09 Dec 2014 — Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) user or (2) password parameter in the bird-feeder page to wp-admin/options-general.php. Múltiples vulnerabilidades CSRF en el plugin Bird Feeder 1.2.3 de WordPress permite a atacantes remotos secuestrar la autenticación de las peticiones de administradores que con... • https://packetstorm.news/files/id/129623 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.5EPSS: 5%CPEs: 1EXPL: 2

23 Aug 2004 — Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users. • https://www.exploit-db.com/exploits/420 •