Skip to content
Noroxi

vdgsecurity records

7 published records for vendor vdgsecurity.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • CVE-2014-9451
    31Monitor

    Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote at

    HighCVSS 7.5No exploitEPSS 5%

    vdgsecurity · vdg senseJan 2, 2015

  • CVE-2014-9575
    26Monitor

    VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrar

    MediumCVSS 6.4No exploitEPSS 2%

    vdgsecurity · vdg senseJan 8, 2015

  • CVE-2014-9452
    21Monitor

    Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0No exploitEPSS 3%

    vdgsecurity · vdg senseJan 2, 2015

  • CVE-2014-9576
    21Monitor

    VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2

    MediumCVSS 5.0No exploitEPSS 2%

    vdgsecurity · vdg senseJan 8, 2015

  • CVE-2014-9578
    21Monitor

    VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers

    MediumCVSS 5.0No exploitEPSS 2%

    vdgsecurity · vdg senseJan 8, 2015

  • CVE-2014-9579
    21Monitor

    VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive informat

    MediumCVSS 5.0No exploitEPSS 2%

    vdgsecurity · vdg senseJan 8, 2015

  • CVE-2014-9577
    17Monitor

    VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain use

    MediumCVSS 4.0No exploitEPSS 2%

    vdgsecurity · vdg senseJan 8, 2015