Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Source Security Information Management HIGH 7.5
CVE-2013-6056

OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability

Fix: 4.3.3.1+
Fix from $1,950 2020-01-27
Open Source Security Information Management CRITICAL 9.8
CVE-2018-7279

A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.

Fix: 5.5.1+
Fix from $2,300 2018-03-14
Unified Security Management MEDIUM 5.7
CVE-2017-14956

AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php…

Fix: after 5.4.2
Fix from $1,600 2017-10-18
Open Source Security Information Management HIGH 7.2
CVE-2015-4046

The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array par…

Fix: after 5.0
Fix from $1,950 2017-05-23
Open Source Security Information Management MEDIUM 6.7
CVE-2015-4045

The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.

Fix: after 5.0
Fix from $1,600 2017-05-23
Ossim CRITICAL 9.8
CVE-2017-6972EPSS 15%

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as roo…

Fix: after 5.3.6
Fix from $2,300 2017-03-22
Ossim HIGH 8.8
CVE-2017-6971EPSS 16%

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, …

Fix: after 5.3.6
Fix from $1,950 2017-03-22
Ossim HIGH 8.4
CVE-2017-6970

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen soc…

Fix: after 5.3.6
Fix from $1,950 2017-03-22
Ossim CRITICAL 9.8
CVE-2016-7955EPSS 6%

The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers …

Fix: after 5.3
Fix from $2,300 2017-03-15
Open Source Security Information And Event Management MEDIUM 6.1
CVE-2016-8583

Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.

Fix: after 5.3.1
Fix from $1,600 2016-10-28
Open Source Security Information And Event Management CRITICAL 9.8
CVE-2016-8582EPSS 57%

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve d…

Fix: after 5.3.1
Fix from $2,300 2016-10-28
Open Source Security Information And Event Management MEDIUM 6.1
CVE-2016-8581EPSS 17%

A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker …

Fix: after 5.3.1
Fix from $1,600 2016-10-28
Open Source Security Information And Event Management CRITICAL 9.8
CVE-2016-8580EPSS 7%

PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary P…

Fix: after 5.3.1
Fix from $2,300 2016-10-28
Open Source Security Information And Event Management MEDIUM 5.4
CVE-2016-6913

Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web script or …

Fix: after 5.2
Fix from $1,600 2016-09-26
Unified Security Management HIGH 9.3
CVE-2015-3446

The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plu…

Fix: after 4.14
Fix from $1,950 2015-05-01
Open Source Security Information Management HIGH 10.0
CVE-2014-5158

The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to exe…

Fix: after 4.5
Fix from $1,950 2014-08-21
Open Source Security Information Management HIGH 10.0
CVE-2014-5210EPSS 15%

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (…

Fix: after 4.6.1
Fix from $1,950 2014-08-21
Open Source Security Information Management HIGH 7.5
CVE-2014-5159

SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands…

Fix: after 4.5
Fix from $1,950 2014-08-21
Open Source Security Information Management MEDIUM 6.5
CVE-2014-5383EPSS 21%

SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vect…

Fix: after 4.6.1
Fix from $1,600 2014-08-21
Open Source Security Information Management HIGH 10.0
CVE-2014-4151EPSS 7%

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a craft…

Fix: after 4.7.0
Fix from $1,950 2014-06-18
Open Source Security Information Management HIGH 10.0
CVE-2014-4152EPSS 6%

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, rel…

Fix: after 4.7.0
Fix from $1,950 2014-06-18
Open Source Security Information Management HIGH 7.8
CVE-2014-4153EPSS 7%

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.

Fix: after 4.7.0
Fix from $1,950 2014-06-18
Open Source Security Information Management HIGH 10.0
CVE-2014-3804EPSS 72%

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_in…

Fix: after 4.6.1
Fix from $1,950 2014-06-13
Open Source Security Information Management HIGH 10.0
CVE-2014-3805EPSS 13%

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)…

Fix: after 4.6.1
Fix from $1,950 2014-06-13
Open Source Security Information Management HIGH 7.5
CVE-2013-5967EPSS 19%

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to ex…

Fix: after 4.3
Fix from $1,950 2013-10-09
Open Source Security Information Management HIGH 7.5
CVE-2013-5321

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitr…

No fix yet
Fix from $1,950 2013-08-20
Open Source Security Information Management MEDIUM 6.5
CVE-2012-3834

SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authen…

No fix yet
Fix from $1,600 2012-07-03
Open Source Security Information Management HIGH 7.5
CVE-2009-4372

AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute …

No fix yet
Fix from $1,950 2009-12-21
Open Source Security Information Management HIGH 7.5
CVE-2009-4373

Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.…

No fix yet
Fix from $1,950 2009-12-21
Open Source Security Information Management HIGH 7.5
CVE-2009-4374

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, an…

Fix: after 2.1.5
Fix from $1,950 2009-12-21