Skip to main content

Vendor archive

cloudflare CVEs

Beta · best-effort

61 CVEs tagged to vendor cloudflare3 Critical, 23 High, 30 Medium, 5 Low, 0 Unrated.

CVE-2022-2145

Published Jun 28, 2022

Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2147

Published Jun 23, 2022

Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was release…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3909

Published Nov 11, 2021

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3761

Published Sep 9, 2021

Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35152

Published Feb 3, 2021

Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an admin…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24356

Published Oct 2, 2020

`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configurat…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-61 of 61 CVEsPage 3 of 3