OpenVAS records
7 published records for vendor openvas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-287 Improper Authentication2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2011-0018Proof of concept | The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execopenvas · openvas manager · CWE-20 | Critical9.0 | — | 9.3% | Jan 28, 2011 |
36Monitor | CVE-2011-1597No exploit | OpenVAS Manager v2.0.3 allows plugin remote code execution.openvas · openvas manager · CWE-434 | High8.8 | — | 1.8% | Feb 5, 2020 |
32Monitor | CVE-2013-6765Proof of concept | OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP openvas · openvas manager · CWE-287 | High7.5 | — | 7.3% | May 19, 2014 |
31Monitor | CVE-2012-5520No exploit | The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands viopenvas · openvas manager · CWE-20 | High7.5 | — | 3.1% | Nov 26, 2012 |
31Monitor | CVE-2014-9220No exploit | SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands vopenvas · openvas manager · CWE-89 | High7.5 | — | 2.1% | Dec 2, 2014 |
30Monitor | CVE-2013-6766No exploit | OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and executopenvas · openvas administrator · CWE-287 | High7.5 | — | 1.6% | May 19, 2014 |
28Monitor | CVE-2011-3351No exploit | openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi iopenvas · openvas-scanner · CWE-59 | High7.1 | — | 0.4% | Nov 25, 2019 |
- CVE-2011-001839Monitor
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to exec
CriticalCVSS 9.0Proof of conceptEPSS 9%openvas · openvas managerJan 28, 2011
- CVE-2011-159736Monitor
OpenVAS Manager v2.0.3 allows plugin remote code execution.
HighCVSS 8.8No exploitEPSS 2%openvas · openvas managerFeb 5, 2020
- CVE-2013-676532Monitor
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP
HighCVSS 7.5Proof of conceptEPSS 7%openvas · openvas managerMay 19, 2014
- CVE-2012-552031Monitor
The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands vi
HighCVSS 7.5No exploitEPSS 3%openvas · openvas managerNov 26, 2012
- CVE-2014-922031Monitor
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5No exploitEPSS 2%openvas · openvas managerDec 2, 2014
- CVE-2013-676630Monitor
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execut
HighCVSS 7.5No exploitEPSS 2%openvas · openvas administratorMay 19, 2014
- CVE-2011-335128Monitor
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi i
HighCVSS 7.1No exploitEPSS 0%openvas · openvas-scannerNov 25, 2019