3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2013-5219
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.5%
2013 2 PoCs

Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

CVE-2019-3972
Comodo Antivirus Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and contains a SharedMemoryDictionary object, which allows a low privileged process to modify the object data causing CmdAgent.exe to crash.

CVE-2019-8933
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
24.4%
2019 1 PoC

In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template Management, clicking on New Template, and modifying the filename from ../index.html to ../index.php.

CVE-2014-9142
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.

CVE-2013-3072
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2013 2 PoCs

An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.

CVE-2019-15711
Fortinet FortiClientLinux Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

CVE-2008-3558
Software Genérico Networking
N/A
UNKNOWN
EPSS
79.9%
2008 1 PoC

Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.

CVE-2023-37849
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.

CVE-2019-16326
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.

CVE-2007-5134
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2007 1 PoC

Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.

CVE-2007-0232
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
10.2%
2007 2 PoCs

PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.

CVE-2014-3792
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewTools_Password and uiViewTools_PasswordConfirm parameters to Forms/tools_admin_1.

CVE-2013-5092
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.5%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

CVE-2019-16905
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

CVE-2019-12576
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the P

CVE-2019-3981
WinBox Networking
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-300 1 PoC

MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

CVE-2013-7417
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2013 2 PoCs

Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery (CSRF) protection mechanism by setting the Referer.

CVE-2019-9657
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.com infrastructure) on the local camera device.

CVE-2020-21936
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.

CVE-2020-10809
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.