nessus software vulnerabilities
vulnerabilities.aspcode.net
Searching nessus software vulnerabilities
Signed integer vulnerability in libnasl in Ness
vulnerability
|
libnasl
|
integer
|
before
|
Nessus
|
Signed
|
Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.
Multiple buffer overflows in libnasl in Nessus
overflows
|
Multiple
|
libnasl
|
before
|
Nessus
|
buffer
|
Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function.
Multiple unknown vulnerabilities in Nessus befo
vulnerabilities
|
Multiple
|
unknown
|
before
|
Nessus
|
Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus."
3com NBX IP VOIP NetSet Configuration Manager a
Configuration
|
attackers
|
service
|
Manager
|
remote
|
denial
|
allows
|
NetSet
|
cause
|
3com
|
VOIP
|
NBX
|
3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.
Alcatel OmniSwitch 7000 and 7800 allows remote
OmniSwitch
|
Alcatel
|
Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.
** DISPUTED ** Nessus 2.0.10a stores account p
passwords
|
plaintext
|
DISPUTED
|
nessusrc
|
account
|
obtain
|
allows
|
Nessus
|
stores
|
local
|
users
|
2010a
|
files
|
which
|
** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue.
centericq 4.20.0-r3 with "Enable peer-to-peer c
communications"
|
peer-to-peer
|
centericq
|
attackers
|
service
|
4200-r3
|
"Enable
|
denial
|
allows
|
remote
|
cause
|
set
|
centericq 4.20.0-r3 with "Enable peer-to-peer communications" set allows remote attackers to cause a denial of service (segmentation fault and crash) via short zero-length packets, and possibly packets of length 1 or 2, as demonstrated using Nessus.
The SISCO OSI stack for Windows, as used by MMS
MMS-EASE
|
Windows
|
stack
|
SISCO
|
used
|
OSI
|
The SISCO OSI stack for Windows, as used by MMS-EASE 7.10 and earlier, AX-S4 MMS 5.01 and earlier, AX-S4 ICCP 3.0103 and earlier, and the ICCP Toolkit for MMS-EASE 4.10 and earlier, allows remote attackers to cause a denial of service (process crash) via certain network traffic, as demonstrated using a Nessus scan.
Nessus before 2.2.8, and 3.x before 3.0.3, allo
before
|
Nessus
|
Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script "can not do anything nasty." This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory.
Unspecified vulnerability in the NCPENGINE in N
vulnerability
|
Unspecified
|
eDirectory
|
NCPENGINE
|
Novell
|
Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause a denial of service (CPU consumption) via unspecified vectors, as originally demonstrated using a Nessus scan.
Polycom SoundPoint IP 301 VoIP Desktop Phone, f
SoundPoint
|
Polycom
|
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a long URL sent to the HTTP daemon and (2) unspecified manipulations as demonstrated by the Nessus http_fingerprinting_hmap.nasl script.
Multiple unspecified vulnerabilities in Firebir
vulnerabilities
|
unspecified
|
attackers
|
Firebird
|
Multiple
|
remote
|
allow
|
Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (application crash) by sending many remote protocol versions; and (2) cause a denial of service (connection drop) via certain network traffic, as demonstrated by Nessus vulnerability scanning.
Cross-site scripting (XSS) vulnerability in the
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Directory traversal vulnerability in a certain
vulnerability
|
Directory
|
traversal
|
control
|
Scanner
|
certain
|
ActiveX
|
Nessus
|
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.
Directory traversal vulnerability in a certain
vulnerability
|
Directory
|
traversal
|
control
|
Scanner
|
certain
|
ActiveX
|
Nessus
|
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. NOTE: this can be leveraged for code execution by writing to a Startup folder.
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in
SCANCTRLScanCtrlCtrl1
|
Vulnerability
|
Scanner
|
scandll
|
ActiveX
|
control
|
Nessus
|
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.
Software vulnerabilities results 1 to 17 of 17
Page:
1