3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2008-1181
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.9%
2008 1 PoC

Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message.

CVE-2008-5776
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.2%
2008 1 PoC

Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to admin.php and the (2) get parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

CVE-2008-4609
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
1.9%
2008 5 PoCs

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.

CVE-2017-15805
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.

CVE-2017-7339
Fortinet FortiPortal Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.

CVE-2017-15271
Software Genérico Networking
N/A
UNKNOWN
EPSS
19.3%
2017 2 PoCs

A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did not automatically restart, which enabled attackers to perform a very effective DoS attack against this service. By sending a crafted SSH identification / version string to the server, a NULL pointer dereference could be caused, apparently because of a race condition in the window message handling, performing the cleanup for invalid connections. This incorrect cleanup code has a use-after-free.

CVE-2017-6297
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.

CVE-2015-1547
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.5%
2015 3 PoCs

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.

CVE-2017-1000062
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.0%
2017 1 PoC

kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution

CVE-2017-3823
Cisco WebEx browser extensions DevOps Networking
N/A
UNKNOWN
EPSS
80.4%
2017 CWE-119 1 PoC

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Me

CVE-2017-14244
Software Genérico Networking
N/A
UNKNOWN
EPSS
50.8%
2017 1 PoC

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

CVE-2017-17540
FortiWLC Networking
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

CVE-2015-7780
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
36.2%
2015 0 PoCs

Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

CVE-2017-12575
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2017 2 PoCs

An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sending a crafted HTTP request to retrieve DHCP clients, firmware version, and network status (ex.: curl -X http://[IP]/aterm_httpif.cgi/negotiate -d "REQ_ID=SUPPORT_IF_GET").

CVE-2017-18373
Software Genérico Networking
N/A
UNKNOWN
EPSS
9.1%
2017 3 PoCs

The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username user3 and and a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.

CVE-2017-3128
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.

CVE-2017-8338
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.9%
2017 4 PoCs

A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.

CVE-2007-2243
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2007 1 PoC

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

CVE-2007-0199
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
1.5%
2007 1 PoC

The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."

CVE-2014-2132
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2014 1 PoC

Cisco WebEx Recording Format (WRF) player and Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allow remote attackers to cause a denial of service (application crash) via a crafted (1) .wrf or (2) .arf file that triggers a buffer over-read, aka Bug ID CSCuh52768.