3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2012-5460
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.

CVE-2012-1366
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.

CVE-2009-4915
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2009 1 PoC

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via unknown network traffic, as demonstrated by a "connection stress test," aka Bug ID CSCsq68451.

CVE-2007-1476
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2007 2 PoCs

The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.

CVE-2014-9462
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2014 1 PoC

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

CVE-2013-6343
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
35.0%
2013 1 PoC

Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.

CVE-2012-2441
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
28.4%
2012 1 PoC

RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.

CVE-2012-1317
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.

CVE-2012-6050
Software Genérico Networking
N/A
UNKNOWN
EPSS
8.6%
2012 2 PoCs

The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.

CVE-2012-1038
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.1%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.

CVE-2012-3935
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832.

CVE-2012-1493
Software Genérico Networking
N/A
UNKNOWN
EPSS
84.4%
2012 1 PoC

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

CVE-2012-5037
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

The ACL implementation in Cisco IOS before 15.1(1)SY on Catalyst 6500 and 7600 devices allows local users to cause a denial of service (device reload) via a "no object-group" command followed by an object-group command, aka Bug ID CSCts16133.

CVE-2012-5723
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-5613
Software Genérico Networking
N/A
UNKNOWN
EPSS
11.1%
2013 2 PoCs

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.

CVE-2012-5017
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.

CVE-2012-5032
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

CVE-2012-5966
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

The restricted telnet shell on the D-Link DSL2730U router allows remote authenticated users to bypass intended command restrictions via shell metacharacters that follow a whitelisted command.

CVE-2012-4097
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter segment types in AS paths, which allows remote attackers to cause a denial of service (BGP service reset) via a malformed UPDATE message, aka Bug ID CSCtn13043.

CVE-2012-5316
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Spam & Virus Firewall 600 Firmware 4.0.1.009 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) Troubleshooting in the Trace route Device module or (2) LDAP Username in the LDAP Configuration module.