3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2017-6444
Software Genérico Networking
N/A
UNKNOWN
EPSS
18.1%
2017 2 PoCs

The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation.

CVE-2007-4292
Software Genérico Networking
N/A
UNKNOWN
EPSS
8.2%
2007 1 PoC

Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1) CSCsf11855, (2) CSCeb21064, (3) CSCse40276, (4) CSCse68355, (5) CSCsf30058, (6) CSCsb24007, and (7) CSCsc60249.

CVE-2007-0471
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.6%
2007 1 PoC

sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.

CVE-2007-0198
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.

CVE-2014-5534
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Princess Shopping (aka air.android.PrincessShopping) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-1569
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a crafted certificate.

CVE-2017-8330
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2017 1 PoC

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devices to interface with the router and interact with the device. It seems that the "NewInMessage" SOAP parameter passed with a huge payload results in crashing the process. If the firmware version AL-R096 is dissected using binwalk tool, we obtain a cpio-root archive which contains the filesystem set up on the device that contains all the binaries. The binary "miniupnpd" is the one that has the vulnerable function that receives the values sent by th

CVE-2017-12426
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVE-2017-6622
Cisco Prime Collaboration Provisioning Web Networking
N/A
UNKNOWN
EPSS
31.0%
2017 CWE-264 1 PoC

A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.

CVE-2017-7731
Fortinet FortiPortal Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.

CVE-2017-9800
Apache Subversion Web Networking
N/A
UNKNOWN
EPSS
59.1%
2017 4 PoCs

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVE-2017-18001
Software Genérico Networking
N/A
UNKNOWN
EPSS
20.8%
2017 1 PoC

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

CVE-2014-2879
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
15.1%
2014 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.

CVE-2015-2281
Software Genérico Networking
N/A
UNKNOWN
EPSS
31.6%
2015 3 PoCs

Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.

CVE-2017-1000117
Software Genérico Networking
N/A
UNKNOWN
EPSS
74.5%
2017 25 PoCs

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVE-2017-6366
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi. NOTE: this issue can be combined with CVE-2017-6334 to execute arbitrary code remotely.

CVE-2017-1000116
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.6%
2017 1 PoC

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

CVE-2017-8116
Software Genérico Networking
N/A
UNKNOWN
EPSS
7.5%
2017 1 PoC

The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.

CVE-2015-0637
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.

CVE-2017-14942
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2017 1 PoC

Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.