3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2023-45285
cmd/go Web Networking
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

CVE-2010-0440
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
30.6%
2010 1 PoC

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.

CVE-2012-1370
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.

CVE-2012-4099
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13065.

CVE-2012-0941
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2012 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list.

CVE-2012-4712
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.

CVE-2010-0150
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2010 1 PoC

Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCsy91157.

CVE-2021-43282
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.

CVE-2012-0360
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

CVE-2012-4658
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.

CVE-2013-3098
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.

CVE-2012-4098
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.

CVE-2012-5687
Software Genérico Networking
N/A
UNKNOWN
EPSS
67.5%
2012 1 PoC

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

CVE-2012-4856
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2012 1 PoC

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2012-2500
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate during WebLaunch of IPsec, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29470.

CVE-2012-2975
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page.

CVE-2012-5014
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.

CVE-2012-5460
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.

CVE-2012-1366
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.

CVE-2007-1476
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2007 2 PoCs

The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.