vdgsecurity records
7 published records for vendor vdgsecurity.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2014-9451No exploit | Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote atvdgsecurity · vdg sense · CWE-119 | High7.5 | — | 4.6% | Jan 2, 2015 |
26Monitor | CVE-2014-9575No exploit | VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrarvdgsecurity · vdg sense · CWE-264 | Medium6.4 | — | 2.4% | Jan 8, 2015 |
21Monitor | CVE-2014-9452No exploit | Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a ..vdgsecurity · vdg sense · CWE-22 | Medium5.0 | — | 2.8% | Jan 2, 2015 |
21Monitor | CVE-2014-9576No exploit | VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2vdgsecurity · vdg sense · CWE-200 | Medium5.0 | — | 2.3% | Jan 8, 2015 |
21Monitor | CVE-2014-9578No exploit | VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers vdgsecurity · vdg sense · CWE-287 | Medium5.0 | — | 2.2% | Jan 8, 2015 |
21Monitor | CVE-2014-9579No exploit | VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive informatvdgsecurity · vdg sense · CWE-200 | Medium5.0 | — | 1.7% | Jan 8, 2015 |
17Monitor | CVE-2014-9577No exploit | VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usevdgsecurity · vdg sense · CWE-200 | Medium4.0 | — | 1.8% | Jan 8, 2015 |
- CVE-2014-945131Monitor
Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote at
HighCVSS 7.5No exploitEPSS 5%vdgsecurity · vdg senseJan 2, 2015
- CVE-2014-957526Monitor
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrar
MediumCVSS 6.4No exploitEPSS 2%vdgsecurity · vdg senseJan 8, 2015
- CVE-2014-945221Monitor
Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0No exploitEPSS 3%vdgsecurity · vdg senseJan 2, 2015
- CVE-2014-957621Monitor
VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2
MediumCVSS 5.0No exploitEPSS 2%vdgsecurity · vdg senseJan 8, 2015
- CVE-2014-957821Monitor
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 2%vdgsecurity · vdg senseJan 8, 2015
- CVE-2014-957921Monitor
VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive informat
MediumCVSS 5.0No exploitEPSS 2%vdgsecurity · vdg senseJan 8, 2015
- CVE-2014-957717Monitor
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain use
MediumCVSS 4.0No exploitEPSS 2%vdgsecurity · vdg senseJan 8, 2015