websense kayıtları
websense üreticisine ait 49 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-255 Credentials Management Errors3
- CWE-20 Improper Input Validation3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
49 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2015-2767İstismar yok | Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."websense · triton ap email | Kritik10,0 | — | %1,4 | 27 Mar 2015 |
40Planlayın | CVE-2015-2763İstismar yok | Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.websense · triton ap email | Kritik10,0 | — | %1,4 | 27 Mar 2015 |
34İzleyin | CVE-2015-2746Kavram kanıtı | The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series websense · triton · CWE-77 | Orta6,5 | — | %25,4 | 26 Mar 2015 |
31İzleyin | CVE-2011-5102İstismar yok | The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfixwebsense · websense web filter · CWE-264 | Yüksek7,5 | — | %3,5 | 23 Ağu 2012 |
30İzleyin | CVE-2015-2772İstismar yok | SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.websense · v-series appliances | Yüksek7,5 | — | %1,1 | 27 Mar 2015 |
30İzleyin | CVE-2017-11177İstismar yok | TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.websense · triton ap email · CWE-20 | Yüksek7,5 | — | %1,0 | 6 Kas 2017 |
27İzleyin | CVE-2015-2769İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allowebsense · triton ap email · CWE-352 | Orta6,8 | — | %0,6 | 27 Mar 2015 |
27İzleyin | CVE-2015-2770İstismar yok | Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote awebsense · v-series appliances · CWE-352 | Orta6,8 | — | %0,6 | 27 Mar 2015 |
22İzleyin | CVE-2007-6312İstismar yok | Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 awebsense · enterpise · CWE-79 | Orta4,3 | — | %15,9 | 11 Ara 2007 |
22İzleyin | CVE-2009-3749Kavram kanıtı | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 awebsense · email security | Orta5,0 | — | %7,6 | 22 Eki 2009 |
21İzleyin | CVE-2015-2748İstismar yok | Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain senwebsense · triton ap data · CWE-200 | Orta5,0 | — | %2,3 | 26 Mar 2015 |
21İzleyin | CVE-2007-6511İstismar yok | Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, orwebsense · enterpise | Orta5,0 | — | %1,8 | 21 Ara 2007 |
20İzleyin | CVE-2010-5149İstismar yok | Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Cwebsense · websense web security | Orta5,0 | — | %1,6 | 23 Ağu 2012 |
20İzleyin | CVE-2009-5131İstismar yok | The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackewebsense · websense email security · CWE-264 | Orta5,0 | — | %1,4 | 26 Ağu 2012 |
20İzleyin | CVE-2012-4605İstismar yok | The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\websense · websense email security · CWE-200 | Orta5,0 | — | %1,4 | 23 Ağu 2012 |
20İzleyin | CVE-2010-5148İstismar yok | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https sesswebsense · websense web filter | Orta5,0 | — | %1,4 | 23 Ağu 2012 |
20İzleyin | CVE-2009-5129İstismar yok | The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (intermittent LDAP authentication outage) viwebsense · websense v10000 · CWE-119 | Orta5,0 | — | %1,3 | 26 Ağu 2012 |
20İzleyin | CVE-2015-2762İstismar yok | Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authenticawebsense · triton ap web · CWE-200 | Orta5,0 | — | %1,3 | 27 Mar 2015 |
20İzleyin | CVE-2009-5132İstismar yok | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a dwebsense · websense web filter | Orta5,0 | — | %1,3 | 26 Ağu 2012 |
20İzleyin | CVE-2009-5128İstismar yok | The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (memory consumption and process crash) via awebsense · websense v10000 · CWE-119 | Orta5,0 | — | %1,2 | 26 Ağu 2012 |
20İzleyin | CVE-2009-5121İstismar yok | Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword websense · websense email security · CWE-264 | Orta5,0 | — | %1,2 | 23 Ağu 2012 |
20İzleyin | CVE-2010-5147İstismar yok | The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers twebsense · websense web security | Orta5,0 | — | %1,2 | 23 Ağu 2012 |
20İzleyin | CVE-2008-7312İstismar yok | The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easiwebsense · enterprise · CWE-20 | Orta5,0 | — | %1,2 | 23 Ağu 2012 |
20İzleyin | CVE-2015-2771İstismar yok | The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers twebsense · triton ap email · CWE-200 | Orta5,0 | — | %1,2 | 27 Mar 2015 |
20İzleyin | CVE-2009-5122İstismar yok | The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive informatiwebsense · websense email security · CWE-200 | Orta5,0 | — | %1,2 | 23 Ağu 2012 |
- CVE-2015-276740Planlayın
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."
KritikCVSS 10,0İstismar yokEPSS %1websense · triton ap email27 Mar 2015
- CVE-2015-276340Planlayın
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.
KritikCVSS 10,0İstismar yokEPSS %1websense · triton ap email27 Mar 2015
- CVE-2015-274634İzleyin
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series
OrtaCVSS 6,5Kavram kanıtıEPSS %25websense · triton26 Mar 2015
- CVE-2011-510231İzleyin
The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix
YüksekCVSS 7,5İstismar yokEPSS %4websense · websense web filter23 Ağu 2012
- CVE-2015-277230İzleyin
SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.
YüksekCVSS 7,5İstismar yokEPSS %1websense · v-series appliances27 Mar 2015
- CVE-2017-1117730İzleyin
TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.
YüksekCVSS 7,5İstismar yokEPSS %1websense · triton ap email6 Kas 2017
- CVE-2015-276927İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allo
OrtaCVSS 6,8İstismar yokEPSS %1websense · triton ap email27 Mar 2015
- CVE-2015-277027İzleyin
Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote a
OrtaCVSS 6,8İstismar yokEPSS %1websense · v-series appliances27 Mar 2015
- CVE-2007-631222İzleyin
Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 a
OrtaCVSS 4,3İstismar yokEPSS %16websense · enterpise11 Ara 2007
- CVE-2009-374922İzleyin
The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 a
OrtaCVSS 5,0Kavram kanıtıEPSS %8websense · email security22 Eki 2009
- CVE-2015-274821İzleyin
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sen
OrtaCVSS 5,0İstismar yokEPSS %2websense · triton ap data26 Mar 2015
- CVE-2007-651121İzleyin
Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, or
OrtaCVSS 5,0İstismar yokEPSS %2websense · enterpise21 Ara 2007
- CVE-2010-514920İzleyin
Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue C
OrtaCVSS 5,0İstismar yokEPSS %2websense · websense web security23 Ağu 2012
- CVE-2009-513120İzleyin
The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attacke
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense email security26 Ağu 2012
- CVE-2012-460520İzleyin
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense email security23 Ağu 2012
- CVE-2010-514820İzleyin
Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https sess
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense web filter23 Ağu 2012
- CVE-2009-512920İzleyin
The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (intermittent LDAP authentication outage) vi
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense v1000026 Ağu 2012
- CVE-2015-276220İzleyin
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentica
OrtaCVSS 5,0İstismar yokEPSS %1websense · triton ap web27 Mar 2015
- CVE-2009-513220İzleyin
The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a d
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense web filter26 Ağu 2012
- CVE-2009-512820İzleyin
The Websense V10000 appliance before 1.0.1 allows remote attackers to cause a denial of service (memory consumption and process crash) via a
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense v1000026 Ağu 2012
- CVE-2009-512120İzleyin
Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense email security23 Ağu 2012
- CVE-2010-514720İzleyin
The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers t
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense web security23 Ağu 2012
- CVE-2008-731220İzleyin
The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easi
OrtaCVSS 5,0İstismar yokEPSS %1websense · enterprise23 Ağu 2012
- CVE-2015-277120İzleyin
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers t
OrtaCVSS 5,0İstismar yokEPSS %1websense · triton ap email27 Mar 2015
- CVE-2009-512220İzleyin
The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive informati
OrtaCVSS 5,0İstismar yokEPSS %1websense · websense email security23 Ağu 2012