alienvault kayıtları
alienvault üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %13,9
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-94 Improper Control of Generation of Code ('Code Injection')7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2014-3804Silahlaştırılmış | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_alienvault · open source security information management · CWE-94 | Kritik10,0 | — | %72,4 | 13 Haz 2014 |
56Planlayın | CVE-2016-8582Silahlaştırılmış | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and ralienvault · open source security information and event management · CWE-89 | Kritik9,8 | — | %57,4 | 28 Eki 2016 |
44Planlayın | CVE-2014-5210Kavram kanıtı | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_alienvault · open source security information management · CWE-94 | Kritik10,0 | — | %14,9 | 21 Ağu 2014 |
44Planlayın | CVE-2014-3805Kavram kanıtı | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_licalienvault · open source security information management · CWE-94 | Kritik10,0 | — | %13,1 | 13 Haz 2014 |
43Planlayın | CVE-2017-6972Kavram kanıtı | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl coalienvault · ossim · CWE-273 | Kritik9,8 | — | %14,6 | 22 Mar 2017 |
42Planlayın | CVE-2014-4151İstismar yok | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vialienvault · open source security information management · CWE-94 | Kritik10,0 | — | %7,3 | 18 Haz 2014 |
42Planlayın | CVE-2014-4152İstismar yok | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task reqalienvault · open source security information management · CWE-94 | Kritik10,0 | — | %5,8 | 18 Haz 2014 |
41Planlayın | CVE-2016-8580Kavram kanıtı | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.alienvault · open source security information and event management · CWE-284 | Kritik9,8 | — | %6,9 | 28 Eki 2016 |
41Planlayın | CVE-2016-7955İstismar yok | The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote aalienvault · ossim · CWE-264 | Kritik9,8 | — | %6,4 | 15 Mar 2017 |
41Planlayın | CVE-2014-5158İstismar yok | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackealienvault · open source security information management · CWE-94 | Kritik10,0 | — | %3,7 | 21 Ağu 2014 |
40Planlayın | CVE-2017-6971Kavram kanıtı | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged alienvault · ossim · CWE-74 | Yüksek8,8 | — | %16,2 | 22 Mar 2017 |
40Planlayın | CVE-2018-7279İstismar yok | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.alienvault · open source security information management | Kritik9,8 | — | %2,4 | 14 Mar 2018 |
38İzleyin | CVE-2015-3446İstismar yok | The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cralienvault · unified security management · CWE-94 | Kritik9,3 | — | %2,4 | 1 May 2015 |
36İzleyin | CVE-2013-5967Silahlaştırılmış | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackalienvault · open source security information management · CWE-89 | Yüksek7,5 | — | %19,0 | 9 Eki 2013 |
34İzleyin | CVE-2017-6970Kavram kanıtı | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an alienvault · ossim · CWE-78 | Yüksek8,4 | — | %1,7 | 22 Mar 2017 |
33İzleyin | CVE-2014-4153Kavram kanıtı | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.alienvault · open source security information management · CWE-200 | Yüksek7,8 | — | %7,4 | 18 Haz 2014 |
32İzleyin | CVE-2014-5383Silahlaştırılmış | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecialienvault · open source security information management · CWE-89 | Orta6,5 | — | %21,2 | 21 Ağu 2014 |
31İzleyin | CVE-2009-4372Kavram kanıtı | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers toalienvault · open source security information management · CWE-20 | Yüksek7,5 | — | %4,8 | 21 Ara 2009 |
31İzleyin | CVE-2009-4373İstismar yok | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSalienvault · open source security information management | Yüksek7,5 | — | %3,0 | 21 Ara 2009 |
31İzleyin | CVE-2013-6056İstismar yok | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerabilityalienvault · open source security information management · CWE-22 | Yüksek7,5 | — | %1,7 | 27 Oca 2020 |
30İzleyin | CVE-2009-4374İstismar yok | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) alienvault · open source security information management · CWE-22 | Yüksek7,5 | — | %1,6 | 21 Ara 2009 |
30İzleyin | CVE-2013-5321Kavram kanıtı | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execualienvault · open source security information management · CWE-89 | Yüksek7,5 | — | %1,4 | 20 Ağu 2013 |
30İzleyin | CVE-2014-5159İstismar yok | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQLalienvault · open source security information management · CWE-89 | Yüksek7,5 | — | %1,3 | 21 Ağu 2014 |
30İzleyin | CVE-2009-4375Kavram kanıtı | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,alienvault · open source security information management · CWE-89 | Yüksek7,5 | — | %1,0 | 21 Ara 2009 |
29İzleyin | CVE-2016-8581Silahlaştırılmış | A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an alienvault · open source security information and event management · CWE-79 | Orta6,1 | — | %17,1 | 28 Eki 2016 |
- CVE-2014-380462Bu hafta
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_
KritikCVSS 10,0SilahlaştırılmışEPSS %72alienvault · open source security information management13 Haz 2014
- CVE-2016-858256Planlayın
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and r
KritikCVSS 9,8SilahlaştırılmışEPSS %57alienvault · open source security information and event management28 Eki 2016
- CVE-2014-521044Planlayın
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_
KritikCVSS 10,0Kavram kanıtıEPSS %15alienvault · open source security information management21 Ağu 2014
- CVE-2014-380544Planlayın
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_lic
KritikCVSS 10,0Kavram kanıtıEPSS %13alienvault · open source security information management13 Haz 2014
- CVE-2017-697243Planlayın
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co
KritikCVSS 9,8Kavram kanıtıEPSS %15alienvault · ossim22 Mar 2017
- CVE-2014-415142Planlayın
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code vi
KritikCVSS 10,0İstismar yokEPSS %7alienvault · open source security information management18 Haz 2014
- CVE-2014-415242Planlayın
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task req
KritikCVSS 10,0İstismar yokEPSS %6alienvault · open source security information management18 Haz 2014
- CVE-2016-858041Planlayın
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2.
KritikCVSS 9,8Kavram kanıtıEPSS %7alienvault · open source security information and event management28 Eki 2016
- CVE-2016-795541Planlayın
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote a
KritikCVSS 9,8İstismar yokEPSS %6alienvault · ossim15 Mar 2017
- CVE-2014-515841Planlayın
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attacke
KritikCVSS 10,0İstismar yokEPSS %4alienvault · open source security information management21 Ağu 2014
- CVE-2017-697140Planlayın
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged
YüksekCVSS 8,8Kavram kanıtıEPSS %16alienvault · ossim22 Mar 2017
- CVE-2018-727940Planlayın
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
KritikCVSS 9,8İstismar yokEPSS %2alienvault · open source security information management14 Mar 2018
- CVE-2015-344638İzleyin
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a cr
KritikCVSS 9,3İstismar yokEPSS %2alienvault · unified security management1 May 2015
- CVE-2013-596736İzleyin
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attack
YüksekCVSS 7,5SilahlaştırılmışEPSS %19alienvault · open source security information management9 Eki 2013
- CVE-2017-697034İzleyin
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an
YüksekCVSS 8,4Kavram kanıtıEPSS %2alienvault · ossim22 Mar 2017
- CVE-2014-415333İzleyin
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
YüksekCVSS 7,8Kavram kanıtıEPSS %7alienvault · open source security information management18 Haz 2014
- CVE-2014-538332İzleyin
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspeci
OrtaCVSS 6,5SilahlaştırılmışEPSS %21alienvault · open source security information management21 Ağu 2014
- CVE-2009-437231İzleyin
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %5alienvault · open source security information management21 Ara 2009
- CVE-2009-437331İzleyin
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OS
YüksekCVSS 7,5İstismar yokEPSS %3alienvault · open source security information management21 Ara 2009
- CVE-2013-605631İzleyin
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
YüksekCVSS 7,5İstismar yokEPSS %2alienvault · open source security information management27 Oca 2020
- CVE-2009-437430İzleyin
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM)
YüksekCVSS 7,5İstismar yokEPSS %2alienvault · open source security information management21 Ara 2009
- CVE-2013-532130İzleyin
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execu
YüksekCVSS 7,5Kavram kanıtıEPSS %1alienvault · open source security information management20 Ağu 2013
- CVE-2014-515930İzleyin
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL
YüksekCVSS 7,5İstismar yokEPSS %1alienvault · open source security information management21 Ağu 2014
- CVE-2009-437530İzleyin
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5,
YüksekCVSS 7,5Kavram kanıtıEPSS %1alienvault · open source security information management21 Ara 2009
- CVE-2016-858129İzleyin
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an
OrtaCVSS 6,1SilahlaştırılmışEPSS %17alienvault · open source security information and event management28 Eki 2016