3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2014-7281
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVE-2015-1457
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.

CVE-2008-3865
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
24.2%
2008 2 PoCs

Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers to execute arbitrary code via a packet with a small value in an unspecified size field.

CVE-2008-0365
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2008 2 PoCs

Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.

CVE-2008-2898
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.8%
2008 1 PoC

Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

CVE-2008-2055
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2008 1 PoC

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.1.x before 7.1(2)70, 7.2.x before 7.2(4), and 8.0.x before 8.0(3)10 allows remote attackers to cause a denial of service via a crafted TCP ACK packet to the device interface.

CVE-2015-5736
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.5%
2015 7 PoCs

The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.

CVE-2008-2733
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2008 1 PoC

Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942.

CVE-2008-5531
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2008 1 PoC

Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

CVE-2008-2285
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2008 1 PoC

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

CVE-2008-7257
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
27.4%
2008 1 PoC

CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involving a %0d%0aLocation%3a sequence in a URI, or conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCsr09163.

CVE-2014-2134
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2014 1 PoC

Heap-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio channel in a .wrf file, aka Bug ID CSCuc39458.

CVE-2015-6811
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
1.8%
2015 2 PoCs

SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.

CVE-2008-3234
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.6%
2008 1 PoC

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.

CVE-2008-5124
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2008 1 PoC

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

CVE-2008-3485
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2008 1 PoC

Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.

CVE-2008-4762
Software Genérico Networking
N/A
UNKNOWN
EPSS
37.0%
2008 3 PoCs

Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argument to the (1) rename and (2) realpath parameters.

CVE-2015-7860
Software Genérico Networking
N/A
UNKNOWN
EPSS
15.7%
2015 1 PoC

Stack-based buffer overflow in the agent in Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending a large amount of data in an environment that lacks relationship-based firewalling.

CVE-2008-2573
Software Genérico Networking
N/A
UNKNOWN
EPSS
16.0%
2008 2 PoCs

Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) command.

CVE-2008-4227
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2008 1 PoC

Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level than was previously used, which makes it easier for remote attackers to obtain sensitive information or hijack a connection by decrypting network traffic.