3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2012-5017
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.

CVE-2012-5032
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

CVE-2012-5966
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

The restricted telnet shell on the D-Link DSL2730U router allows remote authenticated users to bypass intended command restrictions via shell metacharacters that follow a whitelisted command.

CVE-2012-4097
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter segment types in AS paths, which allows remote attackers to cause a denial of service (BGP service reset) via a malformed UPDATE message, aka Bug ID CSCtn13043.

CVE-2012-5316
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Spam & Virus Firewall 600 Firmware 4.0.1.009 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) Troubleshooting in the Trace route Device module or (2) LDAP Username in the LDAP Configuration module.

CVE-2012-3486
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2012 1 PoC

Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon occurrence of an OpenVPN event.

CVE-2012-1921
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2012 1 PoC

Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attackers to hijack the authentication of administrators for requests that change the router passphrase via the pskValue parameter.

CVE-2014-5024
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter.

CVE-2013-2767
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.

CVE-2012-3062
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a network that contains many IPv6 hosts, aka Bug ID CSCtr88193.

CVE-2012-3579
Software Genérico Networking
N/A
UNKNOWN
EPSS
36.4%
2012 1 PoC

Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.

CVE-2012-4923
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.0%
2012 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.

CVE-2012-0217
Software Genérico Networking Database Windows
N/A
UNKNOWN
EPSS
88.0%
2012 4 PoCs

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application.

CVE-2012-1777
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
1.2%
2012 2 PoCs

SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.

CVE-2012-4638
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.

CVE-2012-4838
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

IBM Flex System Chassis Management Module (CMM) and Integrated Management Module 2 (IMM2) allow local users to obtain sensitive information about (1) local accounts, (2) SSH private keys, (3) SSL/TLS private keys, (4) SNMPv3 communities, and (5) LDAP credentials by leveraging unspecified side effects of service or maintenance activity.

CVE-2013-3312
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.

CVE-2012-2499
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.

CVE-2012-2498
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

CVE-2012-0358
Software Genérico Networking
N/A
UNKNOWN
EPSS
6.7%
2012 1 PoC

Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through the Clientless VPN feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 through 7.2 before 7.2(5.6), 8.0 before 8.0(5.26), 8.1 before 8.1(2.53), 8.2 before 8.2(5.18), 8.3 before 8.3(2.28), 8.2 before 8.4(2.16), and 8.6 before 8.6(1.1), allows remote attackers to execute arbitrary code via unspecified vectors, aka Bug ID CSCtr00165.