Vulnerabilities > Berkeley

DATE CVE VULNERABILITY TITLE RISK
2020-02-20 CVE-2013-2018 SQL Injection vulnerability in Berkeley Boinc
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
berkeley CWE-89
critical
9.8
2018-12-20 CVE-2018-1000875 Improper Authentication vulnerability in Berkeley Open Infrastructure for Network Computing 1.0.0/1.0.1/1.0.2
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account.
network
low complexity
berkeley CWE-287
critical
9.8