Splunk / Universal Forwarder
62 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-20298 | Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgrade | HIGH | 8.0 | Jun 2, 2025 |
| CVE-2023-32712 | Unauthenticated Log Injection in Splunk Enterprise | HIGH | 8.6 | Jun 1, 2023 |
| CVE-2023-27538 | curl: SSH connection too eager reuse still | HIGH | 7.7 | Mar 30, 2023 |
| CVE-2023-27537 | curl: HSTS double-free | MEDIUM | 5.9 | Mar 30, 2023 |
| CVE-2023-27536 | curl: GSS delegation too eager connection re-use | MEDIUM | 5.9 | Mar 30, 2023 |
| CVE-2023-27535 | curl: FTP too eager connection reuse | MEDIUM | 5.9 | Mar 30, 2023 |
| CVE-2023-27534 | curl: SFTP path ~ resolving discrepancy | HIGH | 8.8 | Mar 30, 2023 |
| CVE-2023-27533 | curl: TELNET option IAC injection | CRITICAL | 9.8 | Mar 30, 2023 |
| CVE-2023-23916 | curl: HTTP multi-header compression denial of service | MEDIUM | 6.5 | Feb 23, 2023 |
| CVE-2023-23915 | curl: HSTS amnesia with --parallel | MEDIUM | 6.5 | Feb 23, 2023 |
| CVE-2023-23914 | curl: HSTS ignored on multiple requests | CRITICAL | 9.1 | Feb 23, 2023 |
| CVE-2022-43552 | curl: Use-after-free triggered by an HTTP proxy deny response | MEDIUM | 5.9 | Feb 9, 2023 |
| CVE-2022-43551 | curl: HSTS bypass via IDN | HIGH | 7.5 | Dec 23, 2022 |
| CVE-2022-35260 | curl: .netrc parser out-of-bounds access | MEDIUM | 6.5 | Dec 5, 2022 |
| CVE-2022-32221 | curl: POST following PUT confusion | CRITICAL | 9.8 | Dec 5, 2022 |
| CVE-2022-36227 | libarchive: NULL pointer dereference in archive_write.c | CRITICAL | 9.8 | Nov 22, 2022 |
| CVE-2022-42916 | curl: HSTS bypass via IDN | HIGH | 7.5 | Oct 29, 2022 |
| CVE-2022-42915 | curl: HTTP proxy double-free | HIGH | 8.1 | Oct 29, 2022 |
| CVE-2022-35252 | curl: Incorrect handling of control code characters in cookies | LOW | 3.7 | Sep 23, 2022 |
| CVE-2021-31566 | libarchive: symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive | HIGH | 7.8 | Aug 23, 2022 |
| CVE-2022-37439 | Malformed ZIP file crashes Universal Forwarders and Splunk Enterprise through file monitoring input | MEDIUM | 5.5 | Aug 16, 2022 |
| CVE-2022-35737 | sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API | HIGH | 7.5 | Aug 3, 2022 |
| CVE-2022-32208 | curl: FTP-KRB bad message verification | MEDIUM | 5.9 | Jul 7, 2022 |
| CVE-2022-32207 | curl: Unpreserved file permissions | CRITICAL | 9.8 | Jul 7, 2022 |
| CVE-2022-32206 | curl: HTTP compression denial of service | MEDIUM | 6.5 | Jul 7, 2022 |
Showing 1 to 25 of 62 CVEs