3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2015-1050
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Response Body field when creating a new user account.

CVE-2017-14492
Software Genérico Networking
N/A
UNKNOWN
EPSS
92.8%
2017 4 PoCs

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.

CVE-2019-6964
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

A heap-based buffer over-read in Service_SetParamStringValue in cosa_x_cisco_com_ddns_dml.c of the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve information disclosure and code execution by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte username, password, or domain, for which the buffer size is insufficient for the final '\0' character. This is related to the CcspCommonLibrary and WebUI modules.

CVE-2017-7737
Fortinet FortiWeb Networking
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.

CVE-2017-7337
Fortinet FortiPortal Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen session and CSRF tokens or the adomName parameter in the /fpc/sec/customer/policy/getAdomVersion request.

CVE-2020-15504
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

CVE-2007-2038
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2007 1 PoC

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug ID CSCsg36361.

CVE-2007-4263
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.4%
2007 1 PoC

Unspecified vulnerability in the server side of the Secure Copy (SCP) implementation in Cisco 12.2-based IOS allows remote authenticated users to read, write or overwrite any file on the device's filesystem via unknown vectors.

CVE-2014-2589
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.0%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.

CVE-2015-6564
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.1%
2015 6 PoCs

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.

CVE-2017-18372
Software Genérico Networking
N/A
UNKNOWN
EPSS
72.2%
2017 3 PoCs

The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.

CVE-2017-0933
EdgeRouter X Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 CWE-352 1 PoC

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.

CVE-2017-1000475
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2017 2 PoCs

FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.

CVE-2015-6352
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891.

CVE-2017-16757
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.

CVE-2017-7734
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.

CVE-2017-7479
openvpn Networking
N/A
UNKNOWN
EPSS
0.2%
2017 CWE-617 1 PoC

OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.

CVE-2014-8428
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2014 1 PoC

Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

CVE-2015-0624
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.

CVE-2017-7478
openvpn Networking
N/A
UNKNOWN
EPSS
4.6%
2017 CWE-617 2 PoCs

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.