CVE-2022-35507

CVSS v3 Score
4.3
Medium

Vulnerability Description

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

CVSS:4.3(Medium)

Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in doubl...

CWE-742017
CVSS:4.3(Medium)

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names c...

CWE-742018
CVSS:4.3(Medium)

cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

CWE-742018
CVSS:4.3(Medium)

A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. ...

CWE-742019
CVSS:4.3(Medium)

Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.

CWE-742019
CVSS:4.3(Medium)

GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.

CWE-742020