Vulnerabilities > Cloudflare > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-01-11 CVE-2022-4457 Unspecified vulnerability in Cloudflare Warp
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack.
local
low complexity
cloudflare
5.5
2021-11-11 CVE-2021-3911 Unchecked Return Value vulnerability in multiple products
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
network
low complexity
cloudflare debian CWE-252
6.5
2021-11-11 CVE-2021-3912 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
network
low complexity
cloudflare debian CWE-770
6.5