Broadcom
broadcom
688 CVEs • 285 products
Products (285)
Click to collapseToggle
Products (285)
Click to collapse
CVEs (688)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response fro...Show more |
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. |
Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker se...Show more |
1Broadcom 2Spring Data Keyvalue Spring Data RedisJul 17, 2026 Jun 10, 2026 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Sp...Show more |
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 thro...Show more |
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5;...Show more |
Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characte...Show more |
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions...Show more |
2Broadcom Vmware2Spring Authorization Server Spring SecurityJul 17, 2026 Jun 10, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and a...Show more |
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an...Show more |
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, ca...Show more |
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13. |
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patter...Show more |
1Broadcom 1Symantec Siteminder Jun 17, 2026 Mar 10, 2026 4.6 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. |
1Broadcom 1Brocade Active Support Connectivity Gateway Jun 17, 2026 Mar 3, 2026 8.3 HIGH· v4 8.8 HIGH· v3 N/A· v2 Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or dis...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 3, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 3, 2026 4.6 MEDIUM· v4 2.3 LOW· v3 N/A· v2 A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwar...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 3, 2026 4.6 MEDIUM· v4 2.3 LOW· v3 N/A· v2 A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to...Show more |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 3, 2026 8.2 HIGH· v4 7.8 HIGH· v3 N/A· v2 A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command. |
1Broadcom 1Fabric Operating System Jun 17, 2026 Feb 3, 2026 8.4 HIGH· v4 7.2 HIGH· v3 N/A· v2 A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary co...Show more |