Vulnerabilities > Cloudflare > High

DATE CVE VULNERABILITY TITLE RISK
2022-06-23 CVE-2022-2147 Unquoted Search Path or Element vulnerability in Cloudflare Warp 2022.2.247.0/2022.2.95.0/2022.3.63.0
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation.
local
low complexity
cloudflare CWE-428
7.8
2021-11-11 CVE-2021-3908 Infinite Loop vulnerability in multiple products
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
network
low complexity
cloudflare debian CWE-835
7.5
2021-11-11 CVE-2021-3909 Resource Exhaustion vulnerability in multiple products
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever.
network
low complexity
cloudflare debian CWE-400
7.5
2021-11-11 CVE-2021-3910 Improper Input Validation vulnerability in multiple products
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
network
low complexity
cloudflare debian CWE-20
7.5
2021-09-09 CVE-2021-3761 Out-of-bounds Write vulnerability in multiple products
Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate.
network
low complexity
cloudflare debian CWE-787
7.5
2021-02-03 CVE-2020-35152 Unquoted Search Path or Element vulnerability in Cloudflare Warp 1.2.2544.0
Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path.
local
low complexity
cloudflare CWE-428
7.8
2020-10-02 CVE-2020-24356 Uncontrolled Search Path Element vulnerability in Cloudflare Cloudflared
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems.
local
low complexity
cloudflare CWE-427
7.8