Записи alienvault
36 опубликованных записей вендора alienvault.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 13,9 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-94 Improper Control of Generation of Code ('Code Injection')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2014-3804Готовый эксплойт | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_alienvault · open source security information management · CWE-94 | Критическая10,0 | — | 72,4 % | 13 июн. 2014 г. |
56В плане | CVE-2016-8582Готовый эксплойт | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and ralienvault · open source security information and event management · CWE-89 | Критическая9,8 | — | 57,4 % | 28 окт. 2016 г. |
44В плане | CVE-2014-5210Proof of concept | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_alienvault · open source security information management · CWE-94 | Критическая10,0 | — | 14,9 % | 21 авг. 2014 г. |
44В плане | CVE-2014-3805Proof of concept | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_licalienvault · open source security information management · CWE-94 | Критическая10,0 | — | 13,1 % | 13 июн. 2014 г. |
43В плане | CVE-2017-6972Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl coalienvault · ossim · CWE-273 | Критическая9,8 | — | 14,6 % | 22 мар. 2017 г. |
42В плане | CVE-2014-4151Эксплойта нет | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vialienvault · open source security information management · CWE-94 | Критическая10,0 | — | 7,3 % | 18 июн. 2014 г. |
42В плане | CVE-2014-4152Эксплойта нет | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task reqalienvault · open source security information management · CWE-94 | Критическая10,0 | — | 5,8 % | 18 июн. 2014 г. |
41В плане | CVE-2016-8580Proof of concept | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.alienvault · open source security information and event management · CWE-284 | Критическая9,8 | — | 6,9 % | 28 окт. 2016 г. |
41В плане | CVE-2016-7955Эксплойта нет | The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote aalienvault · ossim · CWE-264 | Критическая9,8 | — | 6,4 % | 15 мар. 2017 г. |
41В плане | CVE-2014-5158Эксплойта нет | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackealienvault · open source security information management · CWE-94 | Критическая10,0 | — | 3,7 % | 21 авг. 2014 г. |
40В плане | CVE-2017-6971Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged alienvault · ossim · CWE-74 | Высокая8,8 | — | 16,2 % | 22 мар. 2017 г. |
40В плане | CVE-2018-7279Эксплойта нет | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.alienvault · open source security information management | Критическая9,8 | — | 2,4 % | 14 мар. 2018 г. |
38Наблюдать | CVE-2015-3446Эксплойта нет | The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cralienvault · unified security management · CWE-94 | Критическая9,3 | — | 2,4 % | 1 мая 2015 г. |
36Наблюдать | CVE-2013-5967Готовый эксплойт | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackalienvault · open source security information management · CWE-89 | Высокая7,5 | — | 19,0 % | 9 окт. 2013 г. |
34Наблюдать | CVE-2017-6970Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an alienvault · ossim · CWE-78 | Высокая8,4 | — | 1,7 % | 22 мар. 2017 г. |
33Наблюдать | CVE-2014-4153Proof of concept | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.alienvault · open source security information management · CWE-200 | Высокая7,8 | — | 7,4 % | 18 июн. 2014 г. |
32Наблюдать | CVE-2014-5383Готовый эксплойт | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecialienvault · open source security information management · CWE-89 | Средняя6,5 | — | 21,2 % | 21 авг. 2014 г. |
31Наблюдать | CVE-2009-4372Proof of concept | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers toalienvault · open source security information management · CWE-20 | Высокая7,5 | — | 4,8 % | 21 дек. 2009 г. |
31Наблюдать | CVE-2009-4373Эксплойта нет | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSalienvault · open source security information management | Высокая7,5 | — | 3,0 % | 21 дек. 2009 г. |
31Наблюдать | CVE-2013-6056Эксплойта нет | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerabilityalienvault · open source security information management · CWE-22 | Высокая7,5 | — | 1,7 % | 27 янв. 2020 г. |
30Наблюдать | CVE-2009-4374Эксплойта нет | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) alienvault · open source security information management · CWE-22 | Высокая7,5 | — | 1,6 % | 21 дек. 2009 г. |
30Наблюдать | CVE-2013-5321Proof of concept | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execualienvault · open source security information management · CWE-89 | Высокая7,5 | — | 1,4 % | 20 авг. 2013 г. |
30Наблюдать | CVE-2014-5159Эксплойта нет | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQLalienvault · open source security information management · CWE-89 | Высокая7,5 | — | 1,3 % | 21 авг. 2014 г. |
30Наблюдать | CVE-2009-4375Proof of concept | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,alienvault · open source security information management · CWE-89 | Высокая7,5 | — | 1,0 % | 21 дек. 2009 г. |
29Наблюдать | CVE-2016-8581Готовый эксплойт | A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an alienvault · open source security information and event management · CWE-79 | Средняя6,1 | — | 17,1 % | 28 окт. 2016 г. |
- CVE-2014-380462На этой неделе
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_
КритическаяCVSS 10,0Готовый эксплойтEPSS 72 %alienvault · open source security information management13 июн. 2014 г.
- CVE-2016-858256В плане
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and r
КритическаяCVSS 9,8Готовый эксплойтEPSS 57 %alienvault · open source security information and event management28 окт. 2016 г.
- CVE-2014-521044В плане
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_
КритическаяCVSS 10,0Proof of conceptEPSS 15 %alienvault · open source security information management21 авг. 2014 г.
- CVE-2014-380544В плане
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_lic
КритическаяCVSS 10,0Proof of conceptEPSS 13 %alienvault · open source security information management13 июн. 2014 г.
- CVE-2017-697243В плане
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co
КритическаяCVSS 9,8Proof of conceptEPSS 15 %alienvault · ossim22 мар. 2017 г.
- CVE-2014-415142В плане
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vi
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %alienvault · open source security information management18 июн. 2014 г.
- CVE-2014-415242В плане
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task req
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %alienvault · open source security information management18 июн. 2014 г.
- CVE-2016-858041В плане
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.
КритическаяCVSS 9,8Proof of conceptEPSS 7 %alienvault · open source security information and event management28 окт. 2016 г.
- CVE-2016-795541В плане
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote a
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %alienvault · ossim15 мар. 2017 г.
- CVE-2014-515841В плане
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attacke
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %alienvault · open source security information management21 авг. 2014 г.
- CVE-2017-697140В плане
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged
ВысокаяCVSS 8,8Proof of conceptEPSS 16 %alienvault · ossim22 мар. 2017 г.
- CVE-2018-727940В плане
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %alienvault · open source security information management14 мар. 2018 г.
- CVE-2015-344638Наблюдать
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cr
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %alienvault · unified security management1 мая 2015 г.
- CVE-2013-596736Наблюдать
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attack
ВысокаяCVSS 7,5Готовый эксплойтEPSS 19 %alienvault · open source security information management9 окт. 2013 г.
- CVE-2017-697034Наблюдать
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an
ВысокаяCVSS 8,4Proof of conceptEPSS 2 %alienvault · ossim22 мар. 2017 г.
- CVE-2014-415333Наблюдать
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
ВысокаяCVSS 7,8Proof of conceptEPSS 7 %alienvault · open source security information management18 июн. 2014 г.
- CVE-2014-538332Наблюдать
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspeci
СредняяCVSS 6,5Готовый эксплойтEPSS 21 %alienvault · open source security information management21 авг. 2014 г.
- CVE-2009-437231Наблюдать
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %alienvault · open source security information management21 дек. 2009 г.
- CVE-2009-437331Наблюдать
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OS
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %alienvault · open source security information management21 дек. 2009 г.
- CVE-2013-605631Наблюдать
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %alienvault · open source security information management27 янв. 2020 г.
- CVE-2009-437430Наблюдать
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %alienvault · open source security information management21 дек. 2009 г.
- CVE-2013-532130Наблюдать
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execu
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %alienvault · open source security information management20 авг. 2013 г.
- CVE-2014-515930Наблюдать
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %alienvault · open source security information management21 авг. 2014 г.
- CVE-2009-437530Наблюдать
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %alienvault · open source security information management21 дек. 2009 г.
- CVE-2016-858129Наблюдать
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an
СредняяCVSS 6,1Готовый эксплойтEPSS 17 %alienvault · open source security information and event management28 окт. 2016 г.