Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
halo halo vulnerabilities and exploits
(subscribe to this query)
6.4
CVSSv2
CVE-2020-19038
File Deletion vulnerability in Halo 0.4.3 via delBackup.
Halo Halo 0.4.3
4.3
CVSSv2
CVE-2018-11011
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
Halo Halo 0.0.2
4.3
CVSSv2
CVE-2018-11012
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
Halo Halo 0.0.2
3.5
CVSSv2
CVE-2019-16890
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
Halo Halo 1.1.0
5
CVSSv2
CVE-2004-1539
Halo: Combat Evolved 1.05 and previous versions allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.
Gearbox Software Halo Combat Evolved 1.2
Gearbox Software Halo Combat Evolved 1.31
Gearbox Software Halo Combat Evolved 1.4
Gearbox Software Halo Combat Evolved 1.5
1 EDB exploit
5
CVSSv2
CVE-2004-1667
Off-by-one error in Halo Combat Evolved 1.04 and previous versions allows remote malicious users to cause a denial of service (server crash) via a long client response.
Gearbox Software Halo Combat Evolved 1.2
Gearbox Software Halo Combat Evolved 1.31
Gearbox Software Halo Combat Evolved 1.4
3.5
CVSSv2
CVE-2022-22123
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server.
Fit2cloud Halo
3.5
CVSSv2
CVE-2022-22124
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.
Fit2cloud Halo
3.5
CVSSv2
CVE-2022-28074
Halo-1.5.0 exists to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
Fit2cloud Halo 1.5.0
3.6
CVSSv2
CVE-2019-5625
The Android mobile application Halo Home prior to 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an malicious user to impersonate...
Eaton Halo Home 1.9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »