Skip to content
Noroxi

alienvault records

36 published records for vendor alienvault.

All records

36 records
  • CVE-2014-3804
    62This week

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_

    CriticalCVSS 10.0WeaponizedEPSS 72%

    alienvault · open source security information managementJun 13, 2014

  • A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and r

    CriticalCVSS 9.8WeaponizedEPSS 57%

    alienvault · open source security information and event managementOct 28, 2016

  • The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_

    CriticalCVSS 10.0Proof of conceptEPSS 15%

    alienvault · open source security information managementAug 21, 2014

  • The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_lic

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    alienvault · open source security information managementJun 13, 2014

  • AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    alienvault · ossimMar 22, 2017

  • The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vi

    CriticalCVSS 10.0No exploitEPSS 7%

    alienvault · open source security information managementJun 18, 2014

  • The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task req

    CriticalCVSS 10.0No exploitEPSS 6%

    alienvault · open source security information managementJun 18, 2014

  • PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    alienvault · open source security information and event managementOct 28, 2016

  • The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote a

    CriticalCVSS 9.8No exploitEPSS 6%

    alienvault · ossimMar 15, 2017

  • The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attacke

    CriticalCVSS 10.0No exploitEPSS 4%

    alienvault · open source security information managementAug 21, 2014

  • AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged

    HighCVSS 8.8Proof of conceptEPSS 16%

    alienvault · ossimMar 22, 2017

  • A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    alienvault · open source security information managementMar 14, 2018

  • CVE-2015-3446
    38Monitor

    The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cr

    CriticalCVSS 9.3No exploitEPSS 2%

    alienvault · unified security managementMay 1, 2015

  • CVE-2013-5967
    36Monitor

    Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attack

    HighCVSS 7.5WeaponizedEPSS 19%

    alienvault · open source security information managementOct 9, 2013

  • CVE-2017-6970
    34Monitor

    AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an

    HighCVSS 8.4Proof of conceptEPSS 2%

    alienvault · ossimMar 22, 2017

  • CVE-2014-4153
    33Monitor

    The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.

    HighCVSS 7.8Proof of conceptEPSS 7%

    alienvault · open source security information managementJun 18, 2014

  • CVE-2014-5383
    32Monitor

    SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspeci

    MediumCVSS 6.5WeaponizedEPSS 21%

    alienvault · open source security information managementAug 21, 2014

  • CVE-2009-4372
    31Monitor

    AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to

    HighCVSS 7.5Proof of conceptEPSS 5%

    alienvault · open source security information managementDec 21, 2009

  • CVE-2009-4373
    31Monitor

    Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OS

    HighCVSS 7.5No exploitEPSS 3%

    alienvault · open source security information managementDec 21, 2009

  • CVE-2013-6056
    31Monitor

    OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability

    HighCVSS 7.5No exploitEPSS 2%

    alienvault · open source security information managementJan 27, 2020

  • CVE-2009-4374
    30Monitor

    Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM)

    HighCVSS 7.5No exploitEPSS 2%

    alienvault · open source security information managementDec 21, 2009

  • CVE-2013-5321
    30Monitor

    Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execu

    HighCVSS 7.5Proof of conceptEPSS 1%

    alienvault · open source security information managementAug 20, 2013

  • CVE-2014-5159
    30Monitor

    SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL

    HighCVSS 7.5No exploitEPSS 1%

    alienvault · open source security information managementAug 21, 2014

  • CVE-2009-4375
    30Monitor

    SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,

    HighCVSS 7.5Proof of conceptEPSS 1%

    alienvault · open source security information managementDec 21, 2009

  • CVE-2016-8581
    29Monitor

    A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an

    MediumCVSS 6.1WeaponizedEPSS 17%

    alienvault · open source security information and event managementOct 28, 2016