Записи nessus
13 опубликованных записей вендора nessus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-255 Credentials Management Errors2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2003-0374Эксплойта нет | Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those idnessus · nessus | Критическая10,0 | — | 1,8 % | 16 июн. 2003 г. |
40В плане | CVE-2007-4061Proof of concept | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or ovnessus · vulnerability scanner | Критическая9,3 | — | 11,2 % | 30 июл. 2007 г. |
33Наблюдать | CVE-2007-4031Proof of concept | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitnessus · vulnerability scanner · CWE-22 | Высокая7,8 | — | 5,7 % | 27 июл. 2007 г. |
32Наблюдать | CVE-2007-4062Proof of concept | The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary finessus · vulnerability scanner · CWE-22 | Высокая7,8 | — | 2,1 % | 30 июл. 2007 г. |
20Наблюдать | CVE-2010-2989Эксплойта нет | nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a requenessus · web server plugin · CWE-200 | Средняя5,0 | — | 1,1 % | 10 авг. 2010 г. |
18Наблюдать | CVE-2007-3546Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject anessus · nessus | Средняя4,3 | — | 1,9 % | 3 июл. 2007 г. |
18Наблюдать | CVE-2003-0372Proof of concept | Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of servicenessus · nessus · CWE-189 | Средняя4,6 | — | 0,9 % | 16 июн. 2003 г. |
17Наблюдать | CVE-2010-2914Эксплойта нет | Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackersnessus · web server plugin · CWE-79 | Средняя4,3 | — | 1,6 % | 30 июл. 2010 г. |
17Наблюдать | CVE-2003-0373Эксплойта нет | Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (conessus · nessus · CWE-119 | Средняя4,4 | — | 0,4 % | 16 июн. 2003 г. |
14Наблюдать | CVE-2004-1445Эксплойта нет | A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows locnessus · nessus | Низкая3,7 | — | 0,3 % | 31 дек. 2004 г. |
11Наблюдать | CVE-2006-2093Эксплойта нет | Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL scripnessus · nessus · CWE-399 | Низкая2,6 | — | 3,6 % | 29 апр. 2006 г. |
8Наблюдать | CVE-2004-2723Эксплойта нет | NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.nessus · nessuswx · CWE-255 | Низкая2,1 | — | 0,3 % | 31 дек. 2004 г. |
8Наблюдать | CVE-2004-2722Эксплойта нет | Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords.nessus · nessus · CWE-255 | Низкая2,1 | — | 0,3 % | 31 дек. 2004 г. |
- CVE-2003-037441В плане
Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those id
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %nessus · nessus16 июн. 2003 г.
- CVE-2007-406140В плане
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or ov
КритическаяCVSS 9,3Proof of conceptEPSS 11 %nessus · vulnerability scanner30 июл. 2007 г.
- CVE-2007-403133Наблюдать
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbit
ВысокаяCVSS 7,8Proof of conceptEPSS 6 %nessus · vulnerability scanner27 июл. 2007 г.
- CVE-2007-406232Наблюдать
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary fi
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %nessus · vulnerability scanner30 июл. 2007 г.
- CVE-2010-298920Наблюдать
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a reque
СредняяCVSS 5,0Эксплойта нетEPSS 1 %nessus · web server plugin10 авг. 2010 г.
- CVE-2007-354618Наблюдать
Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject a
СредняяCVSS 4,3Эксплойта нетEPSS 2 %nessus · nessus3 июл. 2007 г.
- CVE-2003-037218Наблюдать
Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service
СредняяCVSS 4,6Proof of conceptEPSS 1 %nessus · nessus16 июн. 2003 г.
- CVE-2010-291417Наблюдать
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers
СредняяCVSS 4,3Эксплойта нетEPSS 2 %nessus · web server plugin30 июл. 2010 г.
- CVE-2003-037317Наблюдать
Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (co
СредняяCVSS 4,4Эксплойта нетEPSS 0 %nessus · nessus16 июн. 2003 г.
- CVE-2004-144514Наблюдать
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows loc
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %nessus · nessus31 дек. 2004 г.
- CVE-2006-209311Наблюдать
Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL scrip
НизкаяCVSS 2,6Эксплойта нетEPSS 4 %nessus · nessus29 апр. 2006 г.
- CVE-2004-27238Наблюдать
NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %nessus · nessuswx31 дек. 2004 г.
- CVE-2004-27228Наблюдать
Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %nessus · nessus31 дек. 2004 г.