Skip to content
Noroxi

NEC records

123 published records for vendor nec.

All records

123 records
  • Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

    CriticalCVSS 9.8No exploitEPSS 45%

    isc · innDec 4, 1996

  • This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.

    HighCVSS 7.5No exploitEPSS 69%

    nec · expresscluster xSep 10, 2020

  • Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

    CriticalCVSS 10.0Proof of conceptEPSS 29%

    data general · dg uxApr 8, 1998

  • NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    nec · univerge sv9100 webpro firmwareDec 26, 2018

  • rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    sgi · irixDec 12, 1995

  • NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    nec · univerge sv9100 webpro firmwareDec 26, 2018

  • Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitra

    CriticalCVSS 10.0No exploitEPSS 7%

    nec · socks 5Dec 31, 2002

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.

    CriticalCVSS 9.8No exploitEPSS 6%

    nec · esmpro managerJul 22, 2020

  • Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.

    CriticalCVSS 10.0No exploitEPSS 3%

    debian · netkitJan 27, 1997

  • Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,

    CriticalCVSS 9.8No exploitEPSS 3%

    nec · baseboard management controllerJan 13, 2021

  • Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with

    CriticalCVSS 9.8No exploitEPSS 3%

    nec · sv9100 firmwareJul 29, 2020

  • Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · clusterpro xNov 2, 2021

  • Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fo

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · clusterpro xNov 2, 2021

  • Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · clusterpro xNov 2, 2021

  • Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · clusterpro xNov 2, 2021

  • Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · clusterpro xNov 2, 2021

  • UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · univerge sv9500 firmwareJan 13, 2021

  • Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sin

    CriticalCVSS 9.8No exploitEPSS 2%

    nec · expresscluster xNov 8, 2022

  • CVE-2023-3741
    39Monitor

    An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · itk-6dgs-1\(bk\)tel firmwareNov 29, 2023

  • UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · univerge wa1020 firmwareMar 11, 2022

  • Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if in

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · sv8100 firmwareJul 29, 2020

  • Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · aterm wg2600hs firmwareApr 25, 2021

  • Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Si

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · expresscluster xNov 8, 2022

  • Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · expresscluster xNov 8, 2022

  • Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CL

    CriticalCVSS 9.8No exploitEPSS 1%

    nec · expresscluster xNov 8, 2022