Vulnerabilities > Cloudflare

DATE CVE VULNERABILITY TITLE RISK
2021-11-11 CVE-2021-3910 Improper Input Validation vulnerability in multiple products
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
network
low complexity
cloudflare debian CWE-20
7.5
2021-11-11 CVE-2021-3911 Unchecked Return Value vulnerability in multiple products
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
network
low complexity
cloudflare debian CWE-252
6.5
2021-11-11 CVE-2021-3912 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
network
low complexity
cloudflare debian CWE-770
6.5
2021-09-09 CVE-2021-3761 Out-of-bounds Write vulnerability in multiple products
Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate.
network
low complexity
cloudflare debian CWE-787
7.5
2021-02-03 CVE-2020-35152 Unquoted Search Path or Element vulnerability in Cloudflare Warp 1.2.2544.0
Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path.
local
low complexity
cloudflare CWE-428
7.8
2020-10-02 CVE-2020-24356 Uncontrolled Search Path Element vulnerability in Cloudflare Cloudflared
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems.
local
low complexity
cloudflare CWE-427
7.8