All CVEs — page 144 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The VeloCloud Orchestrator (VCO) on-premises version has a critical vulnerability that allows remote attackers to access privileged internal functionality, compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.
The flaw allows a truncated label to be decoded incorrectly, leading to a different code point being derived. This can cause a sender to pick a label that resolves to a name on one installation but is rejected on another.
The flaw in Net::IDN::Punycode allows attackers to cause a denial of service by sending invalid labels, leading to excessive memory allocation.
The flaw allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.