3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2015-1028
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
21.1%
2015 4 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy Configuration Panel); the (2) brName parameter to lancfg2get.cgi (Lan Configuration Panel); the (3) wlAuthMode, (4) wl_wsc_reg, or (5) wl_wsc_mode parameter to wlsecrefresh.wl (Wireless Security Panel); or the (6) wlWpaPsk parameter to wlsecurity.wl (Wireless Password Viewer).

CVE-2003-0190
Software Genérico Networking
N/A
UNKNOWN
EPSS
20.6%
2003 5 PoCs

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

CVE-2003-0982
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.9%
2003 1 PoC

Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.

CVE-2003-0386
Software Genérico Networking
N/A
UNKNOWN
EPSS
9.6%
2003 1 PoC

OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.

CVE-2003-0100
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.1%
2003 2 PoCs

Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.

CVE-2007-5027
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.4%
2007 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.

CVE-2007-0066
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
27.7%
2007 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."

CVE-2007-3176
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2007 1 PoC

Unspecified vulnerability in Ingate Firewall and SIParator before 4.5.2 allows remote authenticated users without full privileges to download a Support Report.

CVE-2007-5337
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
1.7%
2007 2 PoCs

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

CVE-2014-2177
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2014 2 PoCs

The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCuh87126.

CVE-2015-1782
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.1%
2015 1 PoC

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

CVE-2003-0567
Software Genérico Networking
N/A
UNKNOWN
EPSS
24.6%
2003 2 PoCs

Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.

CVE-2003-0219
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.8%
2003 1 PoC

Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.

CVE-2003-0511
Software Genérico Networking
N/A
UNKNOWN
EPSS
15.4%
2003 1 PoC

The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.

CVE-2003-1001
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2003 1 PoC

Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.

CVE-2015-5358
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.9%
2015 1 PoC

Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D16, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (mbuf and connection consumption and restart) via a large number of requests that trigger a TCP connection to move to the LAST_ACK

CVE-2003-0731
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2003 1 PoC

CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.

CVE-2003-0258
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.3%
2003 1 PoC

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.

CVE-2003-1002
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2003 1 PoC

Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

CVE-2003-1562
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2003 2 PoCs

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.