3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2015-7289
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2015 1 PoC

Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password derived from a serial number, which makes it easier for remote attackers to obtain access via the web management interface, SSH, TELNET, or SNMP.

CVE-2009-4918
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2009 1 PoC

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439.

CVE-2009-4118
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2009 1 PoC

The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.

CVE-2009-4916
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2009 1 PoC

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (console hang) via a login action during failover replication, aka Bug ID CSCsq80095.

CVE-2009-1560
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2009 1 PoC

The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pass_wd.htm and (2) Wsecurity.htm, which allows remote attackers to obtain sensitive information by reading the HTML source code.

CVE-2014-2595
Software Genérico Networking
N/A
UNKNOWN
EPSS
57.5%
2014 3 PoCs

Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

CVE-2015-2840
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter.

CVE-2009-4910
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2009 1 PoC

Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418.

CVE-2009-1561
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
6.4%
2009 1 PoC

Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.

CVE-2009-4919
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2009 1 PoC

Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to have an unspecified impact via long IKE attributes, aka Bug ID CSCsu43121.

CVE-2009-4921
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2009 1 PoC

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (traceback) via malformed TCP packets, aka Bug ID CSCsm84110.

CVE-2015-4077
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2015 4 PoCs

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.

CVE-2009-2878
Software Genérico Networking Cloud Windows
N/A
UNKNOWN
EPSS
2.5%
2009 1 PoC

Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file, a different vulnerability than CVE-2009-2876 and CVE-2009-2879.

CVE-2009-0620
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2009 1 PoC

Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.

CVE-2009-1262
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2009 1 PoC

Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name.

CVE-2007-3776
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2007 1 PoC

Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.

CVE-2014-3289
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, as demonstrated by the date_range parameter to monitor/reports/overview on the IronPort ESA, aka Bug IDs CSCun07998, CSCun07844, and CSCun07888.

CVE-2015-8325
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 2 PoCs

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.

CVE-2009-3555
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.0%
2009 19 PoCs

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that i

CVE-2009-4643
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.1%
2009 1 PoC

Stack-based buffer overflow in dsInstallerService.dll in the Juniper Installer Service, as used in Juniper Odyssey Access Client 4.72.11421.0 and other products, allows remote attackers to execute arbitrary code via a long string in a malformed DSSETUPSERVICE_CMD_UNINSTALL command to the NeoterisSetupService named pipe.