Записи websense
49 опубликованных записей вендора websense.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-255 Credentials Management Errors3
- CWE-20 Improper Input Validation3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
49 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2015-2767Эксплойта нет | Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."websense · triton ap email | Критическая10,0 | — | 1,4 % | 27 мар. 2015 г. |
40В плане | CVE-2015-2763Эксплойта нет | Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.websense · triton ap email | Критическая10,0 | — | 1,4 % | 27 мар. 2015 г. |
34Наблюдать | CVE-2015-2746Proof of concept | The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series websense · triton · CWE-77 | Средняя6,5 | — | 25,4 % | 26 мар. 2015 г. |
31Наблюдать | CVE-2011-5102Эксплойта нет | The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfixwebsense · websense web filter · CWE-264 | Высокая7,5 | — | 3,5 % | 23 авг. 2012 г. |
30Наблюдать | CVE-2015-2772Эксплойта нет | SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.websense · v-series appliances | Высокая7,5 | — | 1,1 % | 27 мар. 2015 г. |
30Наблюдать | CVE-2017-11177Эксплойта нет | TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.websense · triton ap email · CWE-20 | Высокая7,5 | — | 1,0 % | 6 нояб. 2017 г. |
27Наблюдать | CVE-2015-2769Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allowebsense · triton ap email · CWE-352 | Средняя6,8 | — | 0,6 % | 27 мар. 2015 г. |
27Наблюдать | CVE-2015-2770Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote awebsense · v-series appliances · CWE-352 | Средняя6,8 | — | 0,6 % | 27 мар. 2015 г. |
22Наблюдать | CVE-2007-6312Эксплойта нет | Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 awebsense · enterpise · CWE-79 | Средняя4,3 | — | 15,9 % | 11 дек. 2007 г. |
22Наблюдать | CVE-2009-3749Proof of concept | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 awebsense · email security | Средняя5,0 | — | 7,6 % | 22 окт. 2009 г. |
21Наблюдать | CVE-2015-2748Эксплойта нет | Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain senwebsense · triton ap data · CWE-200 | Средняя5,0 | — | 2,3 % | 26 мар. 2015 г. |
21Наблюдать | CVE-2007-6511Эксплойта нет | Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, orwebsense · enterpise | Средняя5,0 | — | 1,8 % | 21 дек. 2007 г. |
20Наблюдать | CVE-2010-5149Эксплойта нет | Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Cwebsense · websense web security | Средняя5,0 | — | 1,6 % | 23 авг. 2012 г. |
20Наблюдать | CVE-2009-5131Эксплойта нет | The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackewebsense · websense email security · CWE-264 | Средняя5,0 | — | 1,4 % | 26 авг. 2012 г. |
20Наблюдать | CVE-2012-4605Эксплойта нет | The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\websense · websense email security · CWE-200 | Средняя5,0 | — | 1,4 % | 23 авг. 2012 г. |
20Наблюдать | CVE-2010-5148Эксплойта нет | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https sesswebsense · websense web filter | Средняя5,0 | — | 1,4 % | 23 авг. 2012 г. |
20Наблюдать | CVE-2009-5129Эксплойта нет | The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (intermittent LDAP authentication outage) viwebsense · websense v10000 · CWE-119 | Средняя5,0 | — | 1,3 % | 26 авг. 2012 г. |
20Наблюдать | CVE-2015-2762Эксплойта нет | Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authenticawebsense · triton ap web · CWE-200 | Средняя5,0 | — | 1,3 % | 27 мар. 2015 г. |
20Наблюдать | CVE-2009-5132Эксплойта нет | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a dwebsense · websense web filter | Средняя5,0 | — | 1,3 % | 26 авг. 2012 г. |
20Наблюдать | CVE-2009-5128Эксплойта нет | The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (memory consumption and process crash) via awebsense · websense v10000 · CWE-119 | Средняя5,0 | — | 1,2 % | 26 авг. 2012 г. |
20Наблюдать | CVE-2009-5121Эксплойта нет | Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword websense · websense email security · CWE-264 | Средняя5,0 | — | 1,2 % | 23 авг. 2012 г. |
20Наблюдать | CVE-2010-5147Эксплойта нет | The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers twebsense · websense web security | Средняя5,0 | — | 1,2 % | 23 авг. 2012 г. |
20Наблюдать | CVE-2008-7312Эксплойта нет | The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easiwebsense · enterprise · CWE-20 | Средняя5,0 | — | 1,2 % | 23 авг. 2012 г. |
20Наблюдать | CVE-2015-2771Эксплойта нет | The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers twebsense · triton ap email · CWE-200 | Средняя5,0 | — | 1,2 % | 27 мар. 2015 г. |
20Наблюдать | CVE-2009-5122Эксплойта нет | The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive informatiwebsense · websense email security · CWE-200 | Средняя5,0 | — | 1,2 % | 23 авг. 2012 г. |
- CVE-2015-276740В плане
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %websense · triton ap email27 мар. 2015 г.
- CVE-2015-276340В плане
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %websense · triton ap email27 мар. 2015 г.
- CVE-2015-274634Наблюдать
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series
СредняяCVSS 6,5Proof of conceptEPSS 25 %websense · triton26 мар. 2015 г.
- CVE-2011-510231Наблюдать
The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %websense · websense web filter23 авг. 2012 г.
- CVE-2015-277230Наблюдать
SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %websense · v-series appliances27 мар. 2015 г.
- CVE-2017-1117730Наблюдать
TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %websense · triton ap email6 нояб. 2017 г.
- CVE-2015-276927Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allo
СредняяCVSS 6,8Эксплойта нетEPSS 1 %websense · triton ap email27 мар. 2015 г.
- CVE-2015-277027Наблюдать
Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote a
СредняяCVSS 6,8Эксплойта нетEPSS 1 %websense · v-series appliances27 мар. 2015 г.
- CVE-2007-631222Наблюдать
Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 a
СредняяCVSS 4,3Эксплойта нетEPSS 16 %websense · enterpise11 дек. 2007 г.
- CVE-2009-374922Наблюдать
The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 a
СредняяCVSS 5,0Proof of conceptEPSS 8 %websense · email security22 окт. 2009 г.
- CVE-2015-274821Наблюдать
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sen
СредняяCVSS 5,0Эксплойта нетEPSS 2 %websense · triton ap data26 мар. 2015 г.
- CVE-2007-651121Наблюдать
Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, or
СредняяCVSS 5,0Эксплойта нетEPSS 2 %websense · enterpise21 дек. 2007 г.
- CVE-2010-514920Наблюдать
Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue C
СредняяCVSS 5,0Эксплойта нетEPSS 2 %websense · websense web security23 авг. 2012 г.
- CVE-2009-513120Наблюдать
The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attacke
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense email security26 авг. 2012 г.
- CVE-2012-460520Наблюдать
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense email security23 авг. 2012 г.
- CVE-2010-514820Наблюдать
Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https sess
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense web filter23 авг. 2012 г.
- CVE-2009-512920Наблюдать
The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (intermittent LDAP authentication outage) vi
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense v1000026 авг. 2012 г.
- CVE-2015-276220Наблюдать
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentica
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · triton ap web27 мар. 2015 г.
- CVE-2009-513220Наблюдать
The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a d
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense web filter26 авг. 2012 г.
- CVE-2009-512820Наблюдать
The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (memory consumption and process crash) via a
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense v1000026 авг. 2012 г.
- CVE-2009-512120Наблюдать
Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense email security23 авг. 2012 г.
- CVE-2010-514720Наблюдать
The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers t
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense web security23 авг. 2012 г.
- CVE-2008-731220Наблюдать
The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easi
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · enterprise23 авг. 2012 г.
- CVE-2015-277120Наблюдать
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers t
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · triton ap email27 мар. 2015 г.
- CVE-2009-512220Наблюдать
The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive informati
СредняяCVSS 5,0Эксплойта нетEPSS 1 %websense · websense email security23 авг. 2012 г.