Записи vdgsecurity
7 опубликованных записей вендора vdgsecurity.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2014-9451Эксплойта нет | Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote atvdgsecurity · vdg sense · CWE-119 | Высокая7,5 | — | 4,6 % | 2 янв. 2015 г. |
26Наблюдать | CVE-2014-9575Эксплойта нет | VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrarvdgsecurity · vdg sense · CWE-264 | Средняя6,4 | — | 2,4 % | 8 янв. 2015 г. |
21Наблюдать | CVE-2014-9452Эксплойта нет | Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a ..vdgsecurity · vdg sense · CWE-22 | Средняя5,0 | — | 2,8 % | 2 янв. 2015 г. |
21Наблюдать | CVE-2014-9576Эксплойта нет | VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2vdgsecurity · vdg sense · CWE-200 | Средняя5,0 | — | 2,3 % | 8 янв. 2015 г. |
21Наблюдать | CVE-2014-9578Эксплойта нет | VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers vdgsecurity · vdg sense · CWE-287 | Средняя5,0 | — | 2,2 % | 8 янв. 2015 г. |
21Наблюдать | CVE-2014-9579Эксплойта нет | VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive informatvdgsecurity · vdg sense · CWE-200 | Средняя5,0 | — | 1,7 % | 8 янв. 2015 г. |
17Наблюдать | CVE-2014-9577Эксплойта нет | VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usevdgsecurity · vdg sense · CWE-200 | Средняя4,0 | — | 1,8 % | 8 янв. 2015 г. |
- CVE-2014-945131Наблюдать
Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote at
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %vdgsecurity · vdg sense2 янв. 2015 г.
- CVE-2014-957526Наблюдать
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrar
СредняяCVSS 6,4Эксплойта нетEPSS 2 %vdgsecurity · vdg sense8 янв. 2015 г.
- CVE-2014-945221Наблюдать
Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Эксплойта нетEPSS 3 %vdgsecurity · vdg sense2 янв. 2015 г.
- CVE-2014-957621Наблюдать
VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2
СредняяCVSS 5,0Эксплойта нетEPSS 2 %vdgsecurity · vdg sense8 янв. 2015 г.
- CVE-2014-957821Наблюдать
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers
СредняяCVSS 5,0Эксплойта нетEPSS 2 %vdgsecurity · vdg sense8 янв. 2015 г.
- CVE-2014-957921Наблюдать
VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive informat
СредняяCVSS 5,0Эксплойта нетEPSS 2 %vdgsecurity · vdg sense8 янв. 2015 г.
- CVE-2014-957717Наблюдать
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain use
СредняяCVSS 4,0Эксплойта нетEPSS 2 %vdgsecurity · vdg sense8 янв. 2015 г.