Записи OpenVAS
7 опубликованных записей вендора openvas.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation2
- CWE-287 Improper Authentication2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2011-0018Proof of concept | The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execopenvas · openvas manager · CWE-20 | Критическая9,0 | — | 9,3 % | 28 янв. 2011 г. |
36Наблюдать | CVE-2011-1597Эксплойта нет | OpenVAS Manager v2.0.3 allows plugin remote code execution.openvas · openvas manager · CWE-434 | Высокая8,8 | — | 1,8 % | 5 февр. 2020 г. |
32Наблюдать | CVE-2013-6765Proof of concept | OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP openvas · openvas manager · CWE-287 | Высокая7,5 | — | 7,3 % | 19 мая 2014 г. |
31Наблюдать | CVE-2012-5520Эксплойта нет | The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands viopenvas · openvas manager · CWE-20 | Высокая7,5 | — | 3,1 % | 26 нояб. 2012 г. |
31Наблюдать | CVE-2014-9220Эксплойта нет | SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands vopenvas · openvas manager · CWE-89 | Высокая7,5 | — | 2,1 % | 2 дек. 2014 г. |
30Наблюдать | CVE-2013-6766Эксплойта нет | OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and executopenvas · openvas administrator · CWE-287 | Высокая7,5 | — | 1,6 % | 19 мая 2014 г. |
28Наблюдать | CVE-2011-3351Эксплойта нет | openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi iopenvas · openvas-scanner · CWE-59 | Высокая7,1 | — | 0,4 % | 25 нояб. 2019 г. |
- CVE-2011-001839Наблюдать
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to exec
КритическаяCVSS 9,0Proof of conceptEPSS 9 %openvas · openvas manager28 янв. 2011 г.
- CVE-2011-159736Наблюдать
OpenVAS Manager v2.0.3 allows plugin remote code execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %openvas · openvas manager5 февр. 2020 г.
- CVE-2013-676532Наблюдать
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %openvas · openvas manager19 мая 2014 г.
- CVE-2012-552031Наблюдать
The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openvas · openvas manager26 нояб. 2012 г.
- CVE-2014-922031Наблюдать
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openvas · openvas manager2 дек. 2014 г.
- CVE-2013-676630Наблюдать
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execut
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openvas · openvas administrator19 мая 2014 г.
- CVE-2011-335128Наблюдать
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi i
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %openvas · openvas-scanner25 нояб. 2019 г.