3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2001-1434
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2001 1 PoC

Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.

CVE-2021-29302
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
10.1%
2021 1 PoC

TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the router by sending a message through the network, which may lead to remote code execution.

CVE-2001-0750
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2001 1 PoC

Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999.

CVE-2015-2841
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.4%
2015 2 PoCs

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.

CVE-2001-0537
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2001 1 PoC

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

CVE-2012-1370
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.

CVE-2012-4099
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13065.

CVE-2012-0941
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2012 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list.

CVE-2012-4712
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.

CVE-2012-0360
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

CVE-2012-4658
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.

CVE-2013-3098
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.

CVE-2012-4098
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.

CVE-2012-5687
Software Genérico Networking
N/A
UNKNOWN
EPSS
67.5%
2012 1 PoC

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

CVE-2012-4856
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2012 1 PoC

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2012-2500
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate during WebLaunch of IPsec, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29470.

CVE-2012-2975
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page.

CVE-2012-5014
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.

CVE-2012-5460
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.

CVE-2012-1366
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.