alienvault records
36 published records for vendor alienvault.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 5 · 13.9%
- Pre-auth RCE
- 15
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-94 Improper Control of Generation of Code ('Code Injection')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2014-3804Weaponized | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_alienvault · open source security information management · CWE-94 | Critical10.0 | — | 72.4% | Jun 13, 2014 |
56Plan | CVE-2016-8582Weaponized | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and ralienvault · open source security information and event management · CWE-89 | Critical9.8 | — | 57.4% | Oct 28, 2016 |
44Plan | CVE-2014-5210Proof of concept | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_alienvault · open source security information management · CWE-94 | Critical10.0 | — | 14.9% | Aug 21, 2014 |
44Plan | CVE-2014-3805Proof of concept | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_licalienvault · open source security information management · CWE-94 | Critical10.0 | — | 13.1% | Jun 13, 2014 |
43Plan | CVE-2017-6972Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl coalienvault · ossim · CWE-273 | Critical9.8 | — | 14.6% | Mar 22, 2017 |
42Plan | CVE-2014-4151No exploit | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vialienvault · open source security information management · CWE-94 | Critical10.0 | — | 7.3% | Jun 18, 2014 |
42Plan | CVE-2014-4152No exploit | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task reqalienvault · open source security information management · CWE-94 | Critical10.0 | — | 5.8% | Jun 18, 2014 |
41Plan | CVE-2016-8580Proof of concept | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.alienvault · open source security information and event management · CWE-284 | Critical9.8 | — | 6.9% | Oct 28, 2016 |
41Plan | CVE-2016-7955No exploit | The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote aalienvault · ossim · CWE-264 | Critical9.8 | — | 6.4% | Mar 15, 2017 |
41Plan | CVE-2014-5158No exploit | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackealienvault · open source security information management · CWE-94 | Critical10.0 | — | 3.7% | Aug 21, 2014 |
40Plan | CVE-2017-6971Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged alienvault · ossim · CWE-74 | High8.8 | — | 16.2% | Mar 22, 2017 |
40Plan | CVE-2018-7279No exploit | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.alienvault · open source security information management | Critical9.8 | — | 2.4% | Mar 14, 2018 |
38Monitor | CVE-2015-3446No exploit | The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cralienvault · unified security management · CWE-94 | Critical9.3 | — | 2.4% | May 1, 2015 |
36Monitor | CVE-2013-5967Weaponized | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackalienvault · open source security information management · CWE-89 | High7.5 | — | 19.0% | Oct 9, 2013 |
34Monitor | CVE-2017-6970Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an alienvault · ossim · CWE-78 | High8.4 | — | 1.7% | Mar 22, 2017 |
33Monitor | CVE-2014-4153Proof of concept | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.alienvault · open source security information management · CWE-200 | High7.8 | — | 7.4% | Jun 18, 2014 |
32Monitor | CVE-2014-5383Weaponized | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecialienvault · open source security information management · CWE-89 | Medium6.5 | — | 21.2% | Aug 21, 2014 |
31Monitor | CVE-2009-4372Proof of concept | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers toalienvault · open source security information management · CWE-20 | High7.5 | — | 4.8% | Dec 21, 2009 |
31Monitor | CVE-2009-4373No exploit | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSalienvault · open source security information management | High7.5 | — | 3.0% | Dec 21, 2009 |
31Monitor | CVE-2013-6056No exploit | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerabilityalienvault · open source security information management · CWE-22 | High7.5 | — | 1.7% | Jan 27, 2020 |
30Monitor | CVE-2009-4374No exploit | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) alienvault · open source security information management · CWE-22 | High7.5 | — | 1.6% | Dec 21, 2009 |
30Monitor | CVE-2013-5321Proof of concept | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execualienvault · open source security information management · CWE-89 | High7.5 | — | 1.4% | Aug 20, 2013 |
30Monitor | CVE-2014-5159No exploit | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQLalienvault · open source security information management · CWE-89 | High7.5 | — | 1.3% | Aug 21, 2014 |
30Monitor | CVE-2009-4375Proof of concept | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,alienvault · open source security information management · CWE-89 | High7.5 | — | 1.0% | Dec 21, 2009 |
29Monitor | CVE-2016-8581Weaponized | A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an alienvault · open source security information and event management · CWE-79 | Medium6.1 | — | 17.1% | Oct 28, 2016 |
- CVE-2014-380462This week
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_
CriticalCVSS 10.0WeaponizedEPSS 72%alienvault · open source security information managementJun 13, 2014
- CVE-2016-858256Plan
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and r
CriticalCVSS 9.8WeaponizedEPSS 57%alienvault · open source security information and event managementOct 28, 2016
- CVE-2014-521044Plan
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_
CriticalCVSS 10.0Proof of conceptEPSS 15%alienvault · open source security information managementAug 21, 2014
- CVE-2014-380544Plan
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_lic
CriticalCVSS 10.0Proof of conceptEPSS 13%alienvault · open source security information managementJun 13, 2014
- CVE-2017-697243Plan
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co
CriticalCVSS 9.8Proof of conceptEPSS 15%alienvault · ossimMar 22, 2017
- CVE-2014-415142Plan
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vi
CriticalCVSS 10.0No exploitEPSS 7%alienvault · open source security information managementJun 18, 2014
- CVE-2014-415242Plan
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task req
CriticalCVSS 10.0No exploitEPSS 6%alienvault · open source security information managementJun 18, 2014
- CVE-2016-858041Plan
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.
CriticalCVSS 9.8Proof of conceptEPSS 7%alienvault · open source security information and event managementOct 28, 2016
- CVE-2016-795541Plan
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote a
CriticalCVSS 9.8No exploitEPSS 6%alienvault · ossimMar 15, 2017
- CVE-2014-515841Plan
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attacke
CriticalCVSS 10.0No exploitEPSS 4%alienvault · open source security information managementAug 21, 2014
- CVE-2017-697140Plan
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged
HighCVSS 8.8Proof of conceptEPSS 16%alienvault · ossimMar 22, 2017
- CVE-2018-727940Plan
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
CriticalCVSS 9.8No exploitEPSS 2%alienvault · open source security information managementMar 14, 2018
- CVE-2015-344638Monitor
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cr
CriticalCVSS 9.3No exploitEPSS 2%alienvault · unified security managementMay 1, 2015
- CVE-2013-596736Monitor
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attack
HighCVSS 7.5WeaponizedEPSS 19%alienvault · open source security information managementOct 9, 2013
- CVE-2017-697034Monitor
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an
HighCVSS 8.4Proof of conceptEPSS 2%alienvault · ossimMar 22, 2017
- CVE-2014-415333Monitor
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
HighCVSS 7.8Proof of conceptEPSS 7%alienvault · open source security information managementJun 18, 2014
- CVE-2014-538332Monitor
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspeci
MediumCVSS 6.5WeaponizedEPSS 21%alienvault · open source security information managementAug 21, 2014
- CVE-2009-437231Monitor
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 5%alienvault · open source security information managementDec 21, 2009
- CVE-2009-437331Monitor
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OS
HighCVSS 7.5No exploitEPSS 3%alienvault · open source security information managementDec 21, 2009
- CVE-2013-605631Monitor
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
HighCVSS 7.5No exploitEPSS 2%alienvault · open source security information managementJan 27, 2020
- CVE-2009-437430Monitor
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM)
HighCVSS 7.5No exploitEPSS 2%alienvault · open source security information managementDec 21, 2009
- CVE-2013-532130Monitor
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execu
HighCVSS 7.5Proof of conceptEPSS 1%alienvault · open source security information managementAug 20, 2013
- CVE-2014-515930Monitor
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL
HighCVSS 7.5No exploitEPSS 1%alienvault · open source security information managementAug 21, 2014
- CVE-2009-437530Monitor
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,
HighCVSS 7.5Proof of conceptEPSS 1%alienvault · open source security information managementDec 21, 2009
- CVE-2016-858129Monitor
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an
MediumCVSS 6.1WeaponizedEPSS 17%alienvault · open source security information and event managementOct 28, 2016