3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2014-0254
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
45.0%
2014 1 PoC

The IPv6 implementation in Microsoft Windows 8, Windows Server 2012, and Windows RT does not properly validate packets, which allows remote attackers to cause a denial of service (system hang) via crafted ICMPv6 Router Advertisement packets, aka "TCP/IP Version 6 (IPv6) Denial of Service Vulnerability."

CVE-2004-0650
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.8%
2004 1 PoC

UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.

CVE-2004-1907
Software Genérico Networking
N/A
UNKNOWN
EPSS
8.9%
2004 1 PoC

The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".

CVE-2004-0308
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2004 1 PoC

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

CVE-2004-1008
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
9.2%
2004 2 PoCs

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

CVE-2015-2294
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.3%
2015 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the WebGUI in pfSense before 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) zone parameter to status_captiveportal.php; (2) if or (3) dragtable parameter to firewall_rules.php; (4) queue parameter in an add action to firewall_shaper.php; (5) id parameter in an edit action to services_unbound_acls.php; or (6) filterlogentries_time, (7) filterlogentries_sourceipaddress, (8) filterlogentries_sourceport, (9) filterlogentries_destinationipaddress, (10) filterlogentries_interfaces, (11) filterlogentries_destinati

CVE-2021-20138
Gryphon Tower router Networking
N/A
UNKNOWN
EPSS
8.2%
2021 2 PoCs

An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the web interface.

CVE-2018-11013
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.1%
2018 1 PoC

Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthenticated remote attackers to execute arbitrary code via a request with a long HTTP Host header.

CVE-2004-1461
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2004 1 PoC

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.

CVE-2004-1454
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.0%
2004 1 PoC

Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.

CVE-2004-0445
Software Genérico Networking
N/A
UNKNOWN
EPSS
34.3%
2004 1 PoC

The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.

CVE-2004-0589
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2004 2 PoCs

Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.

CVE-2004-2126
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2004 1 PoC

The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.

CVE-2004-1322
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.8%
2004 1 PoC

Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.

CVE-2013-7310
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2013 2 PoCs

The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2004-1436
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2004 1 PoC

The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.

CVE-2004-0307
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2004 1 PoC

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.

CVE-2004-0674
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2004 1 PoC

Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.

CVE-2004-0306
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2004 1 PoC

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.

CVE-2004-1432
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.3%
2004 1 PoC

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed (1) IP or (2) ICMP packets.