websense records
49 published records for vendor websense.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-255 Credentials Management Errors3
- CWE-20 Improper Input Validation3
The weakness classes this vendor ships most often: where to look.
CWEAll records
49 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-2767No exploit | Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."websense · triton ap email | Critical10.0 | — | 1.4% | Mar 27, 2015 |
40Plan | CVE-2015-2763No exploit | Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.websense · triton ap email | Critical10.0 | — | 1.4% | Mar 27, 2015 |
34Monitor | CVE-2015-2746Proof of concept | The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series websense · triton · CWE-77 | Medium6.5 | — | 25.4% | Mar 26, 2015 |
31Monitor | CVE-2011-5102No exploit | The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfixwebsense · websense web filter · CWE-264 | High7.5 | — | 3.5% | Aug 23, 2012 |
30Monitor | CVE-2015-2772No exploit | SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.websense · v-series appliances | High7.5 | — | 1.1% | Mar 27, 2015 |
30Monitor | CVE-2017-11177No exploit | TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.websense · triton ap email · CWE-20 | High7.5 | — | 1.0% | Nov 6, 2017 |
27Monitor | CVE-2015-2769No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allowebsense · triton ap email · CWE-352 | Medium6.8 | — | 0.6% | Mar 27, 2015 |
27Monitor | CVE-2015-2770No exploit | Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote awebsense · v-series appliances · CWE-352 | Medium6.8 | — | 0.6% | Mar 27, 2015 |
22Monitor | CVE-2007-6312No exploit | Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 awebsense · enterpise · CWE-79 | Medium4.3 | — | 15.9% | Dec 11, 2007 |
22Monitor | CVE-2009-3749Proof of concept | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 awebsense · email security | Medium5.0 | — | 7.6% | Oct 22, 2009 |
21Monitor | CVE-2015-2748No exploit | Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain senwebsense · triton ap data · CWE-200 | Medium5.0 | — | 2.3% | Mar 26, 2015 |
21Monitor | CVE-2007-6511No exploit | Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, orwebsense · enterpise | Medium5.0 | — | 1.8% | Dec 21, 2007 |
20Monitor | CVE-2010-5149No exploit | Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Cwebsense · websense web security | Medium5.0 | — | 1.6% | Aug 23, 2012 |
20Monitor | CVE-2009-5131No exploit | The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackewebsense · websense email security · CWE-264 | Medium5.0 | — | 1.4% | Aug 26, 2012 |
20Monitor | CVE-2012-4605No exploit | The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\websense · websense email security · CWE-200 | Medium5.0 | — | 1.4% | Aug 23, 2012 |
20Monitor | CVE-2010-5148No exploit | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https sesswebsense · websense web filter | Medium5.0 | — | 1.4% | Aug 23, 2012 |
20Monitor | CVE-2009-5129No exploit | The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (intermittent LDAP authentication outage) viwebsense · websense v10000 · CWE-119 | Medium5.0 | — | 1.3% | Aug 26, 2012 |
20Monitor | CVE-2015-2762No exploit | Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authenticawebsense · triton ap web · CWE-200 | Medium5.0 | — | 1.3% | Mar 27, 2015 |
20Monitor | CVE-2009-5132No exploit | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a dwebsense · websense web filter | Medium5.0 | — | 1.3% | Aug 26, 2012 |
20Monitor | CVE-2009-5128No exploit | The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (memory consumption and process crash) via awebsense · websense v10000 · CWE-119 | Medium5.0 | — | 1.2% | Aug 26, 2012 |
20Monitor | CVE-2009-5121No exploit | Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword websense · websense email security · CWE-264 | Medium5.0 | — | 1.2% | Aug 23, 2012 |
20Monitor | CVE-2010-5147No exploit | The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers twebsense · websense web security | Medium5.0 | — | 1.2% | Aug 23, 2012 |
20Monitor | CVE-2008-7312No exploit | The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easiwebsense · enterprise · CWE-20 | Medium5.0 | — | 1.2% | Aug 23, 2012 |
20Monitor | CVE-2015-2771No exploit | The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers twebsense · triton ap email · CWE-200 | Medium5.0 | — | 1.2% | Mar 27, 2015 |
20Monitor | CVE-2009-5122No exploit | The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive informatiwebsense · websense email security · CWE-200 | Medium5.0 | — | 1.2% | Aug 23, 2012 |
- CVE-2015-276740Plan
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."
CriticalCVSS 10.0No exploitEPSS 1%websense · triton ap emailMar 27, 2015
- CVE-2015-276340Plan
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.
CriticalCVSS 10.0No exploitEPSS 1%websense · triton ap emailMar 27, 2015
- CVE-2015-274634Monitor
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series
MediumCVSS 6.5Proof of conceptEPSS 25%websense · tritonMar 26, 2015
- CVE-2011-510231Monitor
The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix
HighCVSS 7.5No exploitEPSS 4%websense · websense web filterAug 23, 2012
- CVE-2015-277230Monitor
SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.
HighCVSS 7.5No exploitEPSS 1%websense · v-series appliancesMar 27, 2015
- CVE-2017-1117730Monitor
TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.
HighCVSS 7.5No exploitEPSS 1%websense · triton ap emailNov 6, 2017
- CVE-2015-276927Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allo
MediumCVSS 6.8No exploitEPSS 1%websense · triton ap emailMar 27, 2015
- CVE-2015-277027Monitor
Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote a
MediumCVSS 6.8No exploitEPSS 1%websense · v-series appliancesMar 27, 2015
- CVE-2007-631222Monitor
Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 a
MediumCVSS 4.3No exploitEPSS 16%websense · enterpiseDec 11, 2007
- CVE-2009-374922Monitor
The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 a
MediumCVSS 5.0Proof of conceptEPSS 8%websense · email securityOct 22, 2009
- CVE-2015-274821Monitor
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sen
MediumCVSS 5.0No exploitEPSS 2%websense · triton ap dataMar 26, 2015
- CVE-2007-651121Monitor
Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, or
MediumCVSS 5.0No exploitEPSS 2%websense · enterpiseDec 21, 2007
- CVE-2010-514920Monitor
Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue C
MediumCVSS 5.0No exploitEPSS 2%websense · websense web securityAug 23, 2012
- CVE-2009-513120Monitor
The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attacke
MediumCVSS 5.0No exploitEPSS 1%websense · websense email securityAug 26, 2012
- CVE-2012-460520Monitor
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\
MediumCVSS 5.0No exploitEPSS 1%websense · websense email securityAug 23, 2012
- CVE-2010-514820Monitor
Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https sess
MediumCVSS 5.0No exploitEPSS 1%websense · websense web filterAug 23, 2012
- CVE-2009-512920Monitor
The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (intermittent LDAP authentication outage) vi
MediumCVSS 5.0No exploitEPSS 1%websense · websense v10000Aug 26, 2012
- CVE-2015-276220Monitor
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentica
MediumCVSS 5.0No exploitEPSS 1%websense · triton ap webMar 27, 2015
- CVE-2009-513220Monitor
The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a d
MediumCVSS 5.0No exploitEPSS 1%websense · websense web filterAug 26, 2012
- CVE-2009-512820Monitor
The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (memory consumption and process crash) via a
MediumCVSS 5.0No exploitEPSS 1%websense · websense v10000Aug 26, 2012
- CVE-2009-512120Monitor
Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword
MediumCVSS 5.0No exploitEPSS 1%websense · websense email securityAug 23, 2012
- CVE-2010-514720Monitor
The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers t
MediumCVSS 5.0No exploitEPSS 1%websense · websense web securityAug 23, 2012
- CVE-2008-731220Monitor
The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easi
MediumCVSS 5.0No exploitEPSS 1%websense · enterpriseAug 23, 2012
- CVE-2015-277120Monitor
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers t
MediumCVSS 5.0No exploitEPSS 1%websense · triton ap emailMar 27, 2015
- CVE-2009-512220Monitor
The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive informati
MediumCVSS 5.0No exploitEPSS 1%websense · websense email securityAug 23, 2012