Known vulnerabilities in Splunk Universal Forwarder - page 3

Software CPE: cpe:2.3:a:splunk:splunk_universal_forwarder:*:*:*:*:*:*:*:*
Total vulnerabilities: 97
Public exploits: 7
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Splunk Universal Forwarder Splunk Universal Forwarder is affected by 97 known vulnerabilities: 1 critical, 9 high, 58 medium, 29 low Critical High Medium Low

Vulnerabilities (97)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU72337 - Allocation of Resources Without Limits or Throttling
CVE-2023-23916
CWE-770 Medium
No
No
8.1.14, 8.2.11, 9.0.5 16.02.2023 SB2023021668
SB2023021670
SB2023021671
and 89 more
#VU66881 - Improper input validation
CVE-2022-35252
CWE-20 Medium
No
No
8.1.14, 8.2.11, 9.0.5 31.08.2022 SB2022083106
SB2022090108
SB2022090217
and 55 more
#VU64685 - Improper Verification of Cryptographic Signature
CVE-2022-32208
CWE-347 Medium
No
No
8.1.14, 8.2.11, 9.0.5 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 73 more
#VU64684 - Incorrect Default Permissions
CVE-2022-32207
CWE-276 Low
No
No
8.1.14, 8.2.11, 9.0.5 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 35 more
#VU64682 - Resource exhaustion
CVE-2022-32206
CWE-400 Medium
No
No
8.1.14, 8.2.11, 9.0.5 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 80 more
#VU63011 - Cleartext Transmission of Sensitive Information
CVE-2022-30115
CWE-319 Low
No
No
8.1.14, 8.2.11, 9.0.5 11.05.2022 SB2022051112
SB2022051170
SB2022072605
and 11 more
#VU63009 - Incorrect Implementation of Authentication Algorithm
CVE-2022-27782
CWE-303 Medium
No
No
8.1.14, 8.2.11, 9.0.5 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 68 more
#VU63008 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-27781
CWE-835 Medium
No
No
8.1.14, 8.2.11, 9.0.5 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 36 more
#VU63007 - Improper input validation
CVE-2022-27780
CWE-20 Low
No
No
8.1.14, 8.2.11, 9.0.5 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 14 more
#VU62644 - Exposure of sensitive information to an unauthorized actor
CVE-2022-27776
CWE-200 Low
No
No
8.1.14, 8.2.11, 9.0.5 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 62 more
#VU55148 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-22922
CWE-611 Medium
No
No
8.1.14, 8.2.11, 9.0.5 21.07.2021 SB2021072108
SB2021072162
SB2021072204
and 27 more
#VU53589 - Use After Free
CVE-2021-22901
CWE-416 High
No
No
8.1.14, 8.2.11, 9.0.5 26.05.2021 SB2021052620
SB2021052711
SB2021052719
and 18 more
#VU53587 - Use of Uninitialized Variable
CVE-2021-22898
CWE-457 Medium
No
No
8.1.14, 8.2.11, 9.0.5 26.05.2021 SB2021052620
SB2021052711
SB2021060128
and 47 more
#VU53584 - Inadequate Encryption Strength
CVE-2021-22897
CWE-326 Low
No
No
8.1.14, 8.2.11, 9.0.5 26.05.2021 SB2021052620
SB2021052719
SB2021060321
and 9 more
#VU51821 - Exposure of sensitive information to an unauthorized actor
CVE-2021-22876
CWE-200 Medium
No
No
8.1.14, 8.2.11, 9.0.5 31.03.2021 SB2021033111
SB2021040104
SB2021040117
and 31 more
#VU48895 - Improper Check for Certificate Revocation
CVE-2020-8286
CWE-299 Medium
No
No
8.1.14, 8.2.11, 9.0.5 09.12.2020 SB2020120902
SB2020120915
SB2020120929
and 30 more
#VU48894 - Uncontrolled Recursion
CVE-2020-8285
CWE-674 Low
No
No
8.1.14, 8.2.11, 9.0.5 09.12.2020 SB2020120902
SB2020120915
SB2020120928
and 37 more
#VU48893 - Exposure of sensitive information to an unauthorized actor
CVE-2020-8284
CWE-200 Medium
No
No
8.1.14, 8.2.11, 9.0.5 09.12.2020 SB2020120902
SB2020120915
SB2020120927
and 31 more
#VU45794 - Expired pointer dereference
CVE-2020-8231
CWE-825 Low
No
No
8.1.14, 8.2.11, 9.0.5 20.08.2020 SB2020081916
SB2020082001
SB2020081920
and 29 more
#VU29290 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2020-8177
CWE-644 Low
No
No
8.1.14, 8.2.11, 9.0.5 25.06.2020 SB2020062511
SB2020062514
SB2020063002
and 27 more


Showing elements 41 - 60 out of 97