3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2014-9754
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVE-2015-6357
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.9%
2015 3 PoCs

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.

CVE-2003-0216
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2003 1 PoC

Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.

CVE-2003-1003
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2003 1 PoC

Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

CVE-2009-4913
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2009 1 PoC

The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) exposes IP services on the "far side of the box," which might allow remote attackers to bypass intended access restrictions via IPv6 packets, aka Bug ID CSCso58622.

CVE-2009-2631
Adaptive Security Appliance Web SSL VPN Web Networking
N/A
UNKNOWN
EPSS
0.8%
2009 CWE-284 3 PoCs

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookie

CVE-2015-2608
Software Genérico Networking Database Cloud
N/A
UNKNOWN
EPSS
2.5%
2015 1 PoC

Unspecified vulnerability in (1) the Oracle Communications Diameter Signaling Router (DSR) component in Oracle Communications Applications 4.1.6 and earlier, 5.1.0 and earlier, 6.0.2 and earlier, and 7.1.0 and earlier; (2) the Oracle Communications Performance Intelligence Center Software component in Oracle Communications Applications 9.0.3 and earlier and 10.1.5 and earlier; (3) the Oracle Communications Policy Management component in Oracle Communications Applications 9.9.0 and earlier, 10.5.0 and earlier, 11.5.0 and earlier, and 12.1.0 and earlier; and (4) the Oracle Communications Tekelec

CVE-2009-4923
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2009 1 PoC

Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162.

CVE-2009-3760
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
8.4%
2009 1 PoC

Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.

CVE-2009-1152
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.5%
2009 1 PoC

Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection.

CVE-2009-3758
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
1.0%
2009 1 PoC

SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

CVE-2007-6708
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2007 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi.

CVE-2014-4868
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.

CVE-2015-8265
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors.

CVE-2009-0468
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2009 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping packets, (3) enable network services, (4) configure a proxy server, and (5) modify other settings via parameters in the query string.

CVE-2009-1558
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.1%
2009 0 PoCs

Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.

CVE-2009-3457
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
15.6%
2009 1 PoC

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.

CVE-2009-2918
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2009 1 PoC

The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of 0.

CVE-2015-6420
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
19.3%
2015 7 PoCs

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) li

CVE-2009-4911
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2009 1 PoC

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device crash) via vectors involving SSL VPN and PPPoE transactions, aka Bug ID CSCsm77958.