3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2007-5042
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Outpost Firewall Pro 4.0.1025.7828 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenProcess, (5) NtOpenSection, (6) NtOpenThread, and (7) NtUnloadDriver kernel SSDT hooks, a partial regression of CVE-2006-7160.

CVE-2007-4886
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.8%
2007 1 PoC

Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs.

CVE-2007-3462
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2007 1 PoC

Cross-site request forgery (CSRF) vulnerability in Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, allows remote attackers to execute commands as arbitrary users, and disable firewalling of the protected network.

CVE-2007-1800
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2007 1 PoC

Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka "NACATTACK." NOTE: this attack might be limited to authenticated users and devices.

CVE-2007-1051
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.17.183 and earlier uses a weak cryptographic hashing function (CRC32) to identify trusted modules, which allows local users to bypass security protections by substituting modified modules that have the same CRC32 value.

CVE-2014-8727
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.

CVE-2015-7362
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2015 1 PoC

Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program.

CVE-2021-31800
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
39.8%
2021 2 PoCs

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.

CVE-2021-34204
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.

CVE-2015-7322
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.

CVE-2021-31538
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.

CVE-2014-9027
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that disable modem lan ports via the (1) enblftp, (2) enblhttp, (3) enblsnmp, (4) enbltelnet, (5) enbltftp, (6) enblicmp, or (7) enblssh parameter to accesslocal.cmd.

CVE-2021-20137
Gryphon Tower router Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2021 1 PoC

A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.

CVE-2021-41987
Software Genérico Networking
N/A
UNKNOWN
EPSS
49.6%
2021 1 PoC

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.

CVE-2021-39510
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
6.5%
2021 1 PoC

An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.

CVE-2021-29415
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversary to recover the private ECC key used during an ECDSA operation.

CVE-2015-6531
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2015 1 PoC

Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.

CVE-2023-33276
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding, it is vulnerable to reflective cross-site scripting (XSS).

CVE-2021-30129
Apache Mina SSHD Web Networking
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

CVE-2021-20134
Quagga Services on D-Link DIR-2640 Routers Networking
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file on the router's filesystem as the log file used by either Quagga service (zebra or ripd). Subsequent log messages will be appended to the file, prefixed by a timestamp and some logging metadata. Remote code execution can be achieved by using this vulnerability to append to a shell script on the router's filesystem, and then awaiting or triggering the execution of that script. A remote, unauthentic