3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2014-3220
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
31.9%
2014 1 PoC

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.

CVE-2014-8529
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2014-6702
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The StarSat International (aka com.conduit.app_b15a1814d2d840198e70e3c235af5e8b.app) application 1.41.54.9222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-4162
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.

CVE-2014-7728
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Logan Banner (aka com.soln.S8B5C1F53B8CBE06D5DE0A0E7E23DCDA7) application 1.0010.b0010 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-3857
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
1.6%
2014 3 PoCs

Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.

CVE-2014-2722
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2014 1 PoC

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

CVE-2014-4019
Software Genérico Networking
N/A
UNKNOWN
EPSS
51.8%
2014 3 PoCs

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.

CVE-2014-9142
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.

CVE-2014-3792
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewTools_Password and uiViewTools_PasswordConfirm parameters to Forms/tools_admin_1.

CVE-2014-4871
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject arbitrary web script or HTML via the wlWpaPsk parameter.

CVE-2014-7136
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via a crafted parameter in a DeviceIoControl API call.

CVE-2014-6501
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via vectors related to SSH.

CVE-2014-8779
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.

CVE-2014-0679
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2014 1 PoC

Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.

CVE-2014-1635
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
82.9%
2014 1 PoC

Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter.

CVE-2014-5868
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2014 2 PoCs

The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-0683
Software Genérico Networking
N/A
UNKNOWN
EPSS
29.4%
2014 1 PoC

The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, which allows remote attackers to obtain administrative access by leveraging the ability to intercept requests, aka Bug IDs CSCul94527, CSCum86264, and CSCum86275.

CVE-2014-2135
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.3%
2014 1 PoC

Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCul87216 and CSCuj07603.

CVE-2014-3394
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.