nessus records
13 published records for vendor nessus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-255 Credentials Management Errors2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2003-0374No exploit | Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those idnessus · nessus | Critical10.0 | — | 1.8% | Jun 16, 2003 |
40Plan | CVE-2007-4061Proof of concept | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or ovnessus · vulnerability scanner | Critical9.3 | — | 11.2% | Jul 30, 2007 |
33Monitor | CVE-2007-4031Proof of concept | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitnessus · vulnerability scanner · CWE-22 | High7.8 | — | 5.7% | Jul 27, 2007 |
32Monitor | CVE-2007-4062Proof of concept | The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary finessus · vulnerability scanner · CWE-22 | High7.8 | — | 2.1% | Jul 30, 2007 |
20Monitor | CVE-2010-2989No exploit | nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a requenessus · web server plugin · CWE-200 | Medium5.0 | — | 1.1% | Aug 10, 2010 |
18Monitor | CVE-2007-3546No exploit | Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject anessus · nessus | Medium4.3 | — | 1.9% | Jul 3, 2007 |
18Monitor | CVE-2003-0372Proof of concept | Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of servicenessus · nessus · CWE-189 | Medium4.6 | — | 0.9% | Jun 16, 2003 |
17Monitor | CVE-2010-2914No exploit | Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackersnessus · web server plugin · CWE-79 | Medium4.3 | — | 1.6% | Jul 30, 2010 |
17Monitor | CVE-2003-0373No exploit | Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (conessus · nessus · CWE-119 | Medium4.4 | — | 0.4% | Jun 16, 2003 |
14Monitor | CVE-2004-1445No exploit | A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows locnessus · nessus | Low3.7 | — | 0.3% | Dec 31, 2004 |
11Monitor | CVE-2006-2093No exploit | Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL scripnessus · nessus · CWE-399 | Low2.6 | — | 3.6% | Apr 29, 2006 |
8Monitor | CVE-2004-2723No exploit | NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.nessus · nessuswx · CWE-255 | Low2.1 | — | 0.3% | Dec 31, 2004 |
8Monitor | CVE-2004-2722No exploit | Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords.nessus · nessus · CWE-255 | Low2.1 | — | 0.3% | Dec 31, 2004 |
- CVE-2003-037441Plan
Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those id
CriticalCVSS 10.0No exploitEPSS 2%nessus · nessusJun 16, 2003
- CVE-2007-406140Plan
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or ov
CriticalCVSS 9.3Proof of conceptEPSS 11%nessus · vulnerability scannerJul 30, 2007
- CVE-2007-403133Monitor
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbit
HighCVSS 7.8Proof of conceptEPSS 6%nessus · vulnerability scannerJul 27, 2007
- CVE-2007-406232Monitor
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary fi
HighCVSS 7.8Proof of conceptEPSS 2%nessus · vulnerability scannerJul 30, 2007
- CVE-2010-298920Monitor
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a reque
MediumCVSS 5.0No exploitEPSS 1%nessus · web server pluginAug 10, 2010
- CVE-2007-354618Monitor
Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 2%nessus · nessusJul 3, 2007
- CVE-2003-037218Monitor
Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service
MediumCVSS 4.6Proof of conceptEPSS 1%nessus · nessusJun 16, 2003
- CVE-2010-291417Monitor
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers
MediumCVSS 4.3No exploitEPSS 2%nessus · web server pluginJul 30, 2010
- CVE-2003-037317Monitor
Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (co
MediumCVSS 4.4No exploitEPSS 0%nessus · nessusJun 16, 2003
- CVE-2004-144514Monitor
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows loc
LowCVSS 3.7No exploitEPSS 0%nessus · nessusDec 31, 2004
- CVE-2006-209311Monitor
Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL scrip
LowCVSS 2.6No exploitEPSS 4%nessus · nessusApr 29, 2006
- CVE-2004-27238Monitor
NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
LowCVSS 2.1No exploitEPSS 0%nessus · nessuswxDec 31, 2004
- CVE-2004-27228Monitor
Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords.
LowCVSS 2.1No exploitEPSS 0%nessus · nessusDec 31, 2004