3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2020-29238
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
49.6%
2020 1 PoC

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

CVE-2019-3463
rssh Networking
N/A
UNKNOWN
EPSS
12.4%
2019 1 PoC

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

CVE-2020-10812
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.

CVE-2006-0244
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
13.8%
2006 2 PoCs

Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root

CVE-2017-7734
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.

CVE-2006-4143
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2006 1 PoC

Netgear FVG318 running firmware 1.0.40 allows remote attackers to cause a denial of service (router reset) via TCP packets with bad checksums.

CVE-2006-2322
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2006 1 PoC

The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.

CVE-2014-8428
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2014 1 PoC

Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

CVE-2020-21933
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.

CVE-2019-13115
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
42.4%
2019 1 PoC

In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.

CVE-2020-13417
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.

CVE-2013-1145
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2013 1 PoC

Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application layer gateway inspection is enabled, allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed SIP messages, aka Bug ID CSCtl99174.

CVE-2019-3943
RouterOS Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-23 1 PoC

MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).

CVE-2020-24034
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2020 3 PoCs

Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value inside of this cookie, and assume the role and permissions of the user specified. By assuming the role of the user internal, which is inaccessible to end users by default, the attacker gains the permissions of the internal account, which includes the ability to flash custom firmware

CVE-2019-6700
Fortinet FortiSIEM Networking
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.

CVE-2020-11966
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

CVE-2020-9292
Fortinet FortiSIEMWindowsAgent Networking Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

CVE-2019-7642
Software Genérico Networking
N/A
UNKNOWN
EPSS
10.9%
2019 1 PoC

D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).

CVE-2020-19323
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required

CVE-2019-7489
Email Security Appliance Networking
N/A
UNKNOWN
EPSS
21.1%
2019 CWE-285 1 PoC

A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.