3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2019-12573
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is not sanitized, which allows a local unprivileged user to overwrite arbitrary files owned by any user on the system, including root. This creates a denial of service condition and possible data loss if leveraged by a malicious local user.

CVE-2019-16155
Fortinet FortiClientLinux Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root with arbitrary content through system backup file via specially crafted "BackupConfig" type IPC client requests to the fctsched process. Further more, FortiClient for Linux 6.2.2 and below allow low privilege user write the system backup file under root privilege through GUI thus can cause root system file overwrite.

CVE-2013-7312
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2013 2 PoCs

The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2019-3924
MikroTik RouterOS Networking
N/A
UNKNOWN
EPSS
11.9%
2019 CWE-441 2 PoCs

MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerability to bypass the router's firewall or for general network scanning activities.

CVE-2007-0058
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.7%
2007 1 PoC

Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.

CVE-2014-3220
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
31.9%
2014 1 PoC

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.

CVE-2013-2678
Software Genérico Networking
N/A
UNKNOWN
EPSS
71.3%
2013 2 PoCs

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.

CVE-2019-5590
FortiWeb Networking
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.

CVE-2008-1180
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
7.7%
2008 1 PoC

Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attackers to inject arbitrary web script or HTML via the delivery_mode parameter.

CVE-2019-9584
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.

CVE-2019-1010136
GPN2.4P21-C-CN Networking
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote.

CVE-2019-17652
Fortinet FortiClientLinux Networking
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched process due the argv data not been well sanitized.

CVE-2014-8529
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2013-3516
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.

CVE-2019-7482
SMA100 Networking
N/A
UNKNOWN
EPSS
64.6%
2019 CWE-121 2 PoCs

Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

CVE-2013-1100
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2013 1 PoC

The HTTP server in Cisco IOS on Catalyst switches does not properly handle TCP socket events, which allows remote attackers to cause a denial of service (device crash) via crafted packets on TCP port (1) 80 or (2) 443, aka Bug ID CSCuc53853.

CVE-2019-14929
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.1%
2019 2 PoCs

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.

CVE-2007-0105
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
1.9%
2007 1 PoC

Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.

CVE-2007-1495
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.

CVE-2014-6702
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The StarSat International (aka com.conduit.app_b15a1814d2d840198e70e3c235af5e8b.app) application 1.41.54.9222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.