Known Vulnerabilities for Log Correlation Engine by Tenable
Listed below are 9 of the newest known vulnerabilities associated with "Log Correlation Engine" by "Tenable".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-23840 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases wher... | 7.5 - HIGH | 2021-02-16 | 2023-11-07 |
| CVE-2021-3449 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 r... | 5.9 - MEDIUM | 2021-03-25 | 2023-11-07 |
| CVE-2020-11023 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing | 6.1 - MEDIUM | 2020-04-29 | 2023-11-07 |
| CVE-2020-11022 | In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing... | 6.1 - MEDIUM | 2020-04-29 | 2023-11-07 |
| CVE-2020-1971 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as E... | 5.9 - MEDIUM | 2020-12-08 | 2023-11-07 |
| CVE-2020-1967 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a... | 7.5 - HIGH | 2020-04-21 | 2023-11-07 |
| CVE-2019-1551 | There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algori... | 5.3 - MEDIUM | 2019-12-06 | 2023-11-07 |
| CVE-2016-9261 | Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated... | 5.4 - MEDIUM | 2017-02-28 | 2021-08-31 |
| CVE-2016-4448 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers ... | 9.8 - CRITICAL | 2016-06-09 | 2023-02-12 |