Skip to main content

Vendor/product archive

splunk / universal_forwarder CVEs

Beta · best-effort

50 CVEs tagged to splunk / universal_forwarder6 Critical, 22 High, 19 Medium, 3 Low, 0 Unrated.

CVE-2025-20298

Published Jun 2, 2025

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions as…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-27538

Published Mar 30, 2023

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified,…

CVSS 5.5 · Medium

CVE-2023-27537

Published Mar 30, 2023

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing acro…

CVSS 5.9 · Medium

CVE-2023-27536

Published Mar 30, 2023

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due…

CVSS 5.9 · Medium

CVE-2023-27535

Published Mar 30, 2023

An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Pr…

CVSS 5.9 · Medium

CVE-2023-27534

Published Mar 30, 2023

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in…

CVSS 8.8 · High

CVE-2023-27533

Published Mar 30, 2023

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet o…

CVSS 8.8 · High

CVE-2023-23916

Published Feb 23, 2023

An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response ca…

CVSS 6.5 · Medium

CVE-2023-23915

Published Feb 23, 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested…

CVSS 6.5 · Medium

CVE-2023-23914

Published Feb 23, 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using i…

CVSS 9.1 · Critical

CVE-2022-35260

Published Dec 5, 2022

curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the e…

CVSS 6.5 · Medium

CVE-2022-32221

Published Dec 5, 2022

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been…

CVSS 9.8 · Critical

CVE-2022-42915

Published Oct 29, 2022

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNE…

CVSS 8.1 · High

CVE-2022-37439

Published Aug 16, 2022

In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the ap…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-32156

Published Jun 15, 2022

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk pla…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30115

Published Jun 2, 2022

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 50 CVEsPage 1 of 2