Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
caldera vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2000-0372
Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.
Caldera Openlinux
8.8
CVSSv3
CVE-2021-42559
An issue exists in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is...
Mitre Caldera
2 Github repositories
8.8
CVSSv3
CVE-2021-42561
An issue exists in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows malicious users to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in ...
Mitre Caldera
1 Github repository
8.1
CVSSv3
CVE-2021-42562
An issue exists in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.
Mitre Caldera
1 Github repository
8.8
CVSSv3
CVE-2020-19907
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and previous versions allows authenticated malicious users to execute any command or service.
Mitre Caldera
6.1
CVSSv3
CVE-2022-40605
MITRE CALDERA prior to 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.
Mitre Caldera
6.1
CVSSv3
CVE-2022-40606
MITRE CALDERA prior to 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
Mitre Caldera
6.1
CVSSv3
CVE-2021-42558
An issue exists in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
Mitre Caldera
1 Github repository
NA
CVE-2002-0105
CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.
Caldera Unixware 7.1.0
NA
CVE-2000-0192
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote malicious users to determine what packages are installed on the system.
Caldera Openlinux 2.3
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »