3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2015-6306
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.5%
2015 3 PoCs

Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.

CVE-2008-0028
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.8%
2008 1 PoC

Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.

CVE-2008-0265
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
11.9%
2008 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories.

CVE-2008-2736
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2008 2 PoCs

Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug ID CSCsq45636.

CVE-2008-7225
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2008 1 PoC

Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151.

CVE-2007-5568
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
3.4%
2007 1 PoC

Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).

CVE-2007-5603
Software Genérico Networking
N/A
UNKNOWN
EPSS
75.8%
2007 2 PoCs

Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.

CVE-2014-5928
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Steganos Online Shield VPN (aka com.steganos.onlineshield) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2008-2059
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2008 1 PoC

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors.

CVE-2008-0097
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.9%
2008 2 PoCs

Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.

CVE-2008-0324
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2008 1 PoC

Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.

CVE-2008-1736
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2008 2 PoCs

Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECT_ATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper validation of a ZwQueryObject result; and unspecified calls to the (2) NtCreateFile and (3) NtSetThreadContext functions, different vectors than CVE-2007-0709.

CVE-2015-0636
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.

CVE-2008-0132
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.5%
2008 3 PoCs

Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.

CVE-2008-4109
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2008 1 PoC

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.

CVE-2008-0027
Software Genérico Networking
N/A
UNKNOWN
EPSS
35.5%
2008 1 PoC

Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.

CVE-2008-0680
Software Genérico Networking
N/A
UNKNOWN
EPSS
6.8%
2008 1 PoC

SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.

CVE-2015-1452
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2015 1 PoC

The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.

CVE-2008-4444
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
1.9%
2008 1 PoC

Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers.

CVE-2008-0228
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.8%
2008 1 PoC

Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.