Known vulnerabilities in Splunk Universal Forwarder - page 4
Vendor:
Splunk Inc.
Software:
Splunk Universal Forwarder
Software CPE:
cpe:2.3:a:splunk:splunk_universal_forwarder:*:*:*:*:*:*:*:*
Website:
https://www.splunk.com/
Total vulnerabilities:
97
Public exploits:
7
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.4.14
10.0.9
10.2.6
10.4.2
9.4.13
9.4.12
10.0.8
10.0.7
10.2.5
10.2.4
10.4.1
10.4.0
10.2.2
10.0.5
9.3.12
9.4.11
10.0.6
10.2.3
9.3.11
9.4.10
9.3.10
9.4.9
10.0.4
10.2.1
10.2.0
9.4.7
9.2.11
9.2.12
9.3.9
9.4.8
10.0.3
10.0.2
9.4.6
9.3.8
9.2.10
9.4.4
9.3.6
9.2.8
9.2.9
9.3.7
9.4.5
10.0.0
10.0.1
9.1.10
9.2.7
9.3.5
9.4.3
1.0.2
9.4.2
9.3.4
9.2.6
9.1.9
1.0.1
9.4.1
9.3.3
9.2.5
9.1.8
1.0.0
9.4.0
9.3.2
9.2.4
9.1.7
9.3.1
9.2.3
9.1.6
9.3.0
9.2.2
9.1.5
9.0.10
9.2.1
9.1.4
9.0.9
9.2.0
9.1.3
9.0.8
9.1.2
9.0.7
9.1.1
9.0.6
8.2.12
9.1.0
9.0.5
9.0.4
9.0.3
9.0.2
9.0.0
8.2.11
8.2.10
8.2.9
8.2.8
8.2.7
8.2.6
8.2.5
8.2.4
8.2.3.1
8.2.3
8.2.2
8.2.1
8.2.0
8.1.14
8.1.13
8.1.12
8.1.10
8.1.9
8.1.8
8.1.7
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.3.9
7.3.8
7.3.7
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.10
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.2.0
7.1.10
7.1.9
7.1.8
7.1.7
7.1.6
7.1.5
7.1.4
7.1.3
7.1.2
7.1.1
7.1.0
7.0.13
7.0.11
7.0.10
7.0.9
7.0.8
7.0.7
7.0.6
7.0.5
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
8.1.11
8.2.7.1
9.0.1
6.1.3
6.1.2
6.1.1
6.1.0
Vulnerabilities (97)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU73831 - Exposure of sensitive information to an unauthorized actor CVE-2023-27538 |
CWE-200 | Medium | 8.1.14, 8.2.11, 9.0.5 | 20.03.2023 |
SB2023032027 SB2023032028 SB2023032044 and 40 more |
||
| #VU73830 - Double Free CVE-2023-27537 |
CWE-415 | High | 8.1.14, 8.2.11, 9.0.5 | 20.03.2023 |
SB2023032027 SB2023032044 SB2023060527 and 15 more |
||
| #VU73829 - State Issues CVE-2023-27536 |
CWE-371 | Medium | 8.1.14, 8.2.11, 9.0.5 | 20.03.2023 |
SB2023032027 SB2023032028 SB2023032044 and 80 more |
||
| #VU73828 - State Issues CVE-2023-27535 |
CWE-371 | Low | 8.1.14, 8.2.11, 9.0.5 | 20.03.2023 |
SB2023032027 SB2023032028 SB2023032044 and 84 more |
||
| #VU73827 - Improper input validation CVE-2023-27534 |
CWE-20 | Low | 8.1.14, 8.2.11, 9.0.5 | 20.03.2023 |
SB2023032027 SB2023032028 SB2023032044 and 45 more |
||
| #VU73826 - Improper input validation CVE-2023-27533 |
CWE-20 | Low | 8.1.14, 8.2.11, 9.0.5 | 20.03.2023 |
SB2023032027 SB2023032028 SB2023032044 and 42 more |
||
| #VU71995 - Use After Free CVE-2023-0215 |
CWE-416 | Medium | 8.1.14, 8.2.11, 9.0.5 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 209 more |
||
| #VU71993 - Information Exposure Through Timing Discrepancy CVE-2022-4304 |
CWE-208 | Medium | 8.1.14, 8.2.11, 9.0.5 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020767 and 222 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 8.1.14, 8.2.11, 9.0.5 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU69582 - NULL Pointer Dereference CVE-2022-36227 |
CWE-476 | Low | 8.1.14, 8.2.11, 9.0.5 | 24.11.2022 |
SB2022112432 SB2022112437 SB2022112438 and 77 more |
||
| #VU62641 - Exposure of sensitive information to an unauthorized actor CVE-2022-27774 |
CWE-200 | Medium | 8.1.14, 8.2.11, 9.0.5 | 27.04.2022 |
SB2022042706 SB2022042803 SB2022042904 and 57 more |
||
| #VU62640 - Improper Authentication CVE-2022-22576 |
CWE-287 | Medium | 8.1.14, 8.2.11, 9.0.5 | 27.04.2022 |
SB2022042706 SB2022042803 SB2022042904 and 60 more |
||
| #VU56615 - Insufficient Verification of Data Authenticity CVE-2021-22947 |
CWE-345 | Medium | 8.1.14, 8.2.11, 9.0.5 | 15.09.2021 |
SB2021091514 SB2021091601 SB2021091715 and 43 more |
||
| #VU56613 - Cleartext Transmission of Sensitive Information CVE-2021-22946 |
CWE-319 | Medium | 8.1.14, 8.2.11, 9.0.5 | 15.09.2021 |
SB2021091514 SB2021091601 SB2021091715 and 53 more |
||
| #VU56610 - Double Free CVE-2021-22945 |
CWE-415 | Low | 8.1.14, 8.2.11, 9.0.5 | 15.09.2021 |
SB2021091514 SB2021091601 SB2021091715 and 20 more |
||
| #VU55149 - Use of Uninitialized Variable CVE-2021-22925 |
CWE-457 | Medium | 8.1.14, 8.2.11, 9.0.5 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072202 and 38 more |
||
| #VU55147 - Improper Certificate Validation CVE-2021-22926 |
CWE-295 | Medium | 8.1.14, 8.2.11, 9.0.5 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072814 and 11 more |
||
| #VU55146 - Improper Certificate Validation CVE-2021-22924 |
CWE-295 | Medium | 8.1.14, 8.2.11, 9.0.5 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072202 and 33 more |
||
| #VU55145 - Insufficiently Protected Credentials CVE-2021-22923 |
CWE-522 | Medium | 8.1.14, 8.2.11, 9.0.5 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072204 and 28 more |
||
| #VU51822 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2021-22890 |
CWE-300 | Medium | 8.1.14, 8.2.11, 9.0.5 | 31.03.2021 |
SB2021033111 SB2021040104 SB2021040117 and 15 more |
Showing elements 61 - 80 out of 97