HOMEVULNERABILITIESVENDORSUniversityofcalifornia

UniversityofcaliforniaCVEs & Vulnerabilities

10 CVEs affecting Universityofcalifornia products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

boinc client 165boinc server 5
CVE-2025-0669HIGH

Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.

7 May 2025
8.8
CVSS
CVE-2025-0668CRITICAL

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.

7 May 2025
9.8
CVSS
CVE-2025-0667MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

7 May 2025
5.4
CVSS
CVE-2025-0666MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

7 May 2025
5.4
CVSS
CVE-2013-2018CRITICAL

Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

20 Feb 2020
9.8
CVSS
CVE-2018-1000875CRITICAL

Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.

20 Dec 2018
9.8
CVSS
CVE-2013-7386MEDIUM

Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the gui_urls item in an account file.

2 Jun 2014
5.0
CVSS
CVE-2013-2298CRITICAL

Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.

2 Jun 2014
9.3
CVSS
CVE-2013-2019CRITICAL

Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple file_signature elements.

2 Jun 2014
9.3
CVSS
CVE-2011-5280MEDIUM

Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cs_trickle.cpp or (2) db/db_base.cpp.

2 Jun 2014
5.0
CVSS
← PrevPage 1 / 1Next →
Universityofcalifornia CVEs & Vulnerabilities — 10 Tracked