Vulnerabilities > Trustwave

DATE CVE VULNERABILITY TITLE RISK
2020-01-21 CVE-2019-19886 Improper Resource Shutdown or Release vulnerability in multiple products
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.
network
low complexity
trustwave fedoraproject CWE-404
7.5
2018-07-03 CVE-2018-13065 Cross-site Scripting vulnerability in Trustwave Modsecurity 3.0.0
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element.
network
low complexity
trustwave CWE-79
6.1
2017-12-31 CVE-2017-18001 Missing Authentication for Critical Function vulnerability in Trustwave Secure web Gateway 11.8.0.27
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.
network
low complexity
trustwave CWE-306
critical
9.8