Vulnerabilities
Vulnerable Software
Nasa:  Security Vulnerabilities
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).
CVSS Score
7.5
EPSS Score
0.001
Published
2024-09-27
An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-05-21
An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-05-21
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.
CVSS Score
7.3
EPSS Score
0.01
Published
2024-05-21
NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-21
An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-05-21
An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-05-21
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-11-09
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-11-09
In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-10-06


Contact Us

Shodan ® - All rights reserved