buffalotech kayıtları
buffalotech üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2016-7824İstismar yok | Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the dbuffalotech · wnc01wh firmware · CWE-284 | Yüksek8,8 | — | %1,6 | 9 Haz 2017 |
35İzleyin | CVE-2016-7822İstismar yok | Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackersbuffalotech · wnc01wh firmware · CWE-352 | Yüksek8,8 | — | %1,0 | 9 Haz 2017 |
35İzleyin | CVE-2016-1134İstismar yok | Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1buffalotech · whr-1166dhp · CWE-352 | Yüksek8,8 | — | %0,5 | 22 Oca 2016 |
30İzleyin | CVE-2014-9284İstismar yok | The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 buffalotech · wsr-600dhp firmware · CWE-78 | Yüksek7,7 | — | %1,1 | 8 Haz 2015 |
27İzleyin | CVE-2016-7826İstismar yok | Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to reabuffalotech · wnc01wh firmware · CWE-22 | Orta6,5 | — | %2,2 | 9 Haz 2017 |
27İzleyin | CVE-2016-7825İstismar yok | Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to reabuffalotech · wnc01wh firmware · CWE-22 | Orta6,5 | — | %2,2 | 9 Haz 2017 |
27İzleyin | CVE-2016-7821İstismar yok | Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the managementbuffalotech · wnc01wh firmware · CWE-20 | Orta6,5 | — | %1,8 | 9 Haz 2017 |
27İzleyin | CVE-2015-8262İstismar yok | Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS qbuffalotech · airstation extreme n600 firmware | Orta6,8 | — | %1,1 | 26 Ara 2015 |
24İzleyin | CVE-2016-1135İstismar yok | Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 andbuffalotech · wmr-300 · CWE-79 | Orta6,1 | — | %0,8 | 22 Oca 2016 |
23İzleyin | CVE-2011-1324İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers wbuffalotech · bbr-4hg firmware · CWE-352 | Orta5,8 | — | %0,5 | 9 May 2011 |
17İzleyin | CVE-2007-4822İstismar yok | Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackebuffalotech · airstation whr-g54s · CWE-352 | Orta4,3 | — | %0,7 | 11 Eyl 2007 |
17İzleyin | CVE-2016-7823İstismar yok | Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inbuffalotech · wnc01wh firmware · CWE-79 | Orta4,3 | — | %0,5 | 9 Haz 2017 |
- CVE-2016-782435İzleyin
Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the d
YüksekCVSS 8,8İstismar yokEPSS %2buffalotech · wnc01wh firmware9 Haz 2017
- CVE-2016-782235İzleyin
Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers
YüksekCVSS 8,8İstismar yokEPSS %1buffalotech · wnc01wh firmware9 Haz 2017
- CVE-2016-113435İzleyin
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1
YüksekCVSS 8,8İstismar yokEPSS %1buffalotech · whr-1166dhp22 Oca 2016
- CVE-2014-928430İzleyin
The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60
YüksekCVSS 7,7İstismar yokEPSS %1buffalotech · wsr-600dhp firmware8 Haz 2015
- CVE-2016-782627İzleyin
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to rea
OrtaCVSS 6,5İstismar yokEPSS %2buffalotech · wnc01wh firmware9 Haz 2017
- CVE-2016-782527İzleyin
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to rea
OrtaCVSS 6,5İstismar yokEPSS %2buffalotech · wnc01wh firmware9 Haz 2017
- CVE-2016-782127İzleyin
Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management
OrtaCVSS 6,5İstismar yokEPSS %2buffalotech · wnc01wh firmware9 Haz 2017
- CVE-2015-826227İzleyin
Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS q
OrtaCVSS 6,8İstismar yokEPSS %1buffalotech · airstation extreme n600 firmware26 Ara 2015
- CVE-2016-113524İzleyin
Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and
OrtaCVSS 6,1İstismar yokEPSS %1buffalotech · wmr-30022 Oca 2016
- CVE-2011-132423İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers w
OrtaCVSS 5,8İstismar yokEPSS %0buffalotech · bbr-4hg firmware9 May 2011
- CVE-2007-482217İzleyin
Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attacke
OrtaCVSS 4,3İstismar yokEPSS %1buffalotech · airstation whr-g54s11 Eyl 2007
- CVE-2016-782317İzleyin
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to in
OrtaCVSS 4,3İstismar yokEPSS %0buffalotech · wnc01wh firmware9 Haz 2017