3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2014-9104
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2014 3 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting established VPN sessions, (2) connect to arbitrary VPN servers, or (3) create VPN profiles and execute arbitrary commands via crafted API requests.

CVE-2014-5455
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2014 2 PoCs

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

CVE-2014-8617
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via the release parameter to module/releasecontrol.

CVE-2014-6603
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.

CVE-2014-4346
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-3486
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.

CVE-2014-6242
Software Genérico Web Networking Database Windows
N/A
UNKNOWN
EPSS
5.7%
2014 2 PoCs

Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

CVE-2014-4154
Software Genérico Networking
N/A
UNKNOWN
EPSS
8.7%
2014 3 PoCs

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.

CVE-2014-2723
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2014 1 PoC

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

CVE-2014-0329
Software Genérico Networking
N/A
UNKNOWN
EPSS
25.0%
2014 2 PoCs

The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the password.

CVE-2014-4727
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.

CVE-2014-8496
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.8%
2014 1 PoC

Digicom DG-5514T ADSL router with firmware 3.2 generates predictable session IDs, which allows remote attackers to gain administrator privileges via a brute force session hijacking attack.

CVE-2014-8475
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
1.3%
2014 1 PoC

FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.

CVE-2014-4927
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
17.5%
2014 1 PoC

Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.

CVE-2014-2721
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2014 1 PoC

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

CVE-2014-4155
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 3 PoCs

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.

CVE-2014-9583
Software Genérico Networking
N/A
UNKNOWN
EPSS
91.0%
2014 3 PoCs

common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD packet to UDP port 9999. NOTE: this issue was incorrectly mapped to CVE-2014-10000, but that ID is invalid due to its use as an example of the 2014 CVE ID syntax change.

CVE-2014-2136
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.3%
2014 1 PoC

Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCui72223, CSCul01163, and CSCul01166.

CVE-2014-2962
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
88.9%
2014 2 PoCs

Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

CVE-2014-4347
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2014 1 PoC

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.