Greenbone records
4 published records for vendor greenbone.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-25016No exploit | Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.greenbone · greenbone security assistant · CWE-74 | Critical9.8 | — | 1.3% | Jun 21, 2021 |
27Monitor | CVE-2011-0650No exploit | Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the agreenbone · greenbone security assistant · CWE-352 | Medium6.8 | — | 1.1% | Jan 28, 2011 |
24Monitor | CVE-2016-1926No exploit | Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackersgreenbone · greenbone security assistant · CWE-79 | Medium6.1 | — | 1.6% | Jan 26, 2016 |
24Monitor | CVE-2019-25047No exploit | Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.greenbone · greenbone security assistant · CWE-79 | Medium6.1 | — | 1.1% | Jun 21, 2021 |
- CVE-2018-2501639Monitor
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
CriticalCVSS 9.8No exploitEPSS 1%greenbone · greenbone security assistantJun 21, 2021
- CVE-2011-065027Monitor
Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the a
MediumCVSS 6.8No exploitEPSS 1%greenbone · greenbone security assistantJan 28, 2011
- CVE-2016-192624Monitor
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers
MediumCVSS 6.1No exploitEPSS 2%greenbone · greenbone security assistantJan 26, 2016
- CVE-2019-2504724Monitor
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
MediumCVSS 6.1No exploitEPSS 1%greenbone · greenbone security assistantJun 21, 2021