Products

Showing 9 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Helix vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthenticated Denial of Service via Auto Generation Function

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.

CWE-400Nov 11, 2024
CVSS8.7v4.0EPSS0.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unauthenticated Denial of Service via Refuse Function

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.

CWE-400Nov 11, 2024
CVSS8.7v4.0EPSS0.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unauthenticated Denial of Service via Shutdown Function

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.

CWE-400Nov 11, 2024
CVSS8.7v4.0EPSS0.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unicode "best fit" argument injection

In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.

CWE-176Sep 24, 2024
CVSS5.8v4.0EPSS0.199%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Command Injection in Helix Sync

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.

CWE-77CWE-94Feb 1, 2024
CVSS3.6v3.1EPSS0.752%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unauthenticated Remote Denial-of-Service via Buffer in Helix Core

In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.

CWE-400Nov 8, 2023
CVSS7.5v3.1EPSS0.947%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unauthenticated Remote Denial-of-Service (Commit) in Helix Core

In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner.

CWE-400Nov 8, 2023
CVSS7.5v3.1EPSS0.946%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Arbitrary Code Execution in Helix Core

An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.

CWE-94Nov 8, 2023
CVSS9.0v3.1EPSS1.12%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Unauthenticated Remote Denial-of-Service via Shutdown Function in Helix Core

In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.

CWE-400Nov 8, 2023
CVSS7.5v3.1EPSS0.947%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX