VYPR

Vendor CVEs

NEC

All CVEs

150 total · sorted by risk
  • CVE-2021-20620MedJan 28, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

  • CVE-2020-5533MedFeb 21, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2024-28016MedMar 28, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…

  • CVE-2026-4621MedMar 27, 2026
    risk 0.36cvss 5.6epss 0.00

    Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.

  • CVE-1999-0011MedApr 8, 1998
    risk 0.36cvss 5.4epss 0.05

    Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

  • CVE-2023-3331MedJun 28, 2023
    risk 0.35cvss 5.4epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all…

  • CVE-2021-44746MedFeb 1, 2022
    risk 0.35cvss 5.3epss 0.01

    UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote…

  • CVE-2021-20712MedApr 26, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed from the WAN side due to the defect in the IPv6 firewall function.

  • CVE-2021-20653MedFeb 17, 2021
    risk 0.35cvss 5.3epss 0.01

    Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote attackers to bypass access restriction and to obtain unauthorized historical data without access privileges via unspecified vectors.

  • CVE-2018-16193MedJan 9, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2024-6466MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.

  • CVE-2024-28013MedMar 28, 2024
    risk 0.34cvss 5.3epss 0.00

    Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP,…

  • CVE-2024-28006MedMar 28, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…

  • CVE-2025-8153MedSep 17, 2025
    risk 0.33cvss epss 0.00

    Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an…

  • CVE-2026-6059MedMay 25, 2026
    risk 0.31cvss epss 0.00

    A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.

  • CVE-2025-0354MedJan 15, 2025
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to…

  • CVE-2024-28005MedMar 28, 2024
    risk 0.31cvss 4.7epss 0.00

    Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N,…

  • CVE-2023-3332MedJun 28, 2023
    risk 0.31cvss 4.8epss 0.00

    Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all…

  • CVE-2020-5684MedDec 24, 2020
    risk 0.31cvss 4.8epss 0.00

    iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted…

  • CVE-2024-11014MedNov 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.

  • CVE-2023-3330MedJun 28, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions…

  • CVE-2023-39341LowAug 9, 2023
    risk 0.21cvss 3.3epss 0.00

    "FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai…

  • CVE-2021-20677LowMar 26, 2021
    risk 0.20cvss 3.1epss 0.01

    UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by…

  • CVE-1999-0009Apr 8, 1998
    risk 0.05cvss epss 0.29

    Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

  • CVE-1999-0208Dec 12, 1995
    risk 0.04cvss epss 0.13

    rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

  • CVE-1999-0040May 1, 1997
    risk 0.03cvss epss 0.01

    Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

  • CVE-2002-2368Dec 31, 2002
    risk 0.01cvss epss 0.07

    Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long username to (1) the GetString function in proxy.c for the SOCKS5 module or (2) the HandleS4Connection function in…

  • CVE-2026-8797HigJun 26, 2026
    risk 0.00cvss epss 0.00

    An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

  • CVE-2013-7314Jan 23, 2014
    risk 0.00cvss epss 0.02

    The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a…

  • CVE-2013-0717Mar 19, 2013
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for…

  • CVE-2013-0706Feb 22, 2013
    risk 0.00cvss epss 0.02

    NEC Universal RAID Utility 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier does not provide access control, which allows remote attackers to perform arbitrary RAID disk operations via unspecified vectors.

  • CVE-2012-2640Jul 5, 2012
    risk 0.00cvss epss 0.01

    The NEC BIGLOBE Yome Collection application 1.8.3 and earlier for Android allows remote attackers to read the IMEI value from an SD card via a crafted application that lacks the READ_PHONE_STATE permission.

  • CVE-2011-1323May 9, 2011
    risk 0.00cvss epss 0.02

    Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted…

  • CVE-2010-1943May 19, 2010
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in NEC CapsSuite Small Edition PatchMeister 2.0 Update2 and earlier allows remote attackers to cause a denial of service (OS shutdown or restart) via vectors related to Client Service for PTM and crafted packets to port 56015.

  • CVE-2010-1941May 19, 2010
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in NEC WebSAM DeploymentManager 5.13 and earlier, as used in SigmaSystemCenter 2.1 Update2 and earlier, BladeSystemCenter, ExpressSystemCenter, and VirtualPCCenter 2.2 and earlier, allows remote attackers to cause a denial of service (OS shutdown or…

  • CVE-2008-0378Jan 22, 2008
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in SocksCap 2.40-051231 and earlier, when "Resolve all names remotely" is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hostname.

  • CVE-2007-5557Oct 18, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known…

  • CVE-2006-6946Jan 23, 2007
    risk 0.00cvss epss 0.01

    The web server in the NEC MultiWriter 1700C allows remote attackers to modify the device configuration via unspecified vectors.

  • CVE-2006-6947Jan 23, 2007
    risk 0.00cvss epss 0.01

    The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

  • CVE-2005-4465Dec 22, 2005
    risk 0.00cvss epss 0.03

    The Internet Key Exchange version 1 (IKEv1) implementation in NEC UNIVERGE IX1000, IX2000, and IX3000 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.…

  • CVE-2002-2367Dec 31, 2002
    risk 0.00cvss epss 0.05

    Off-by-one buffer overflow in NEC SOCKS5 1.0 r11 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hostname.

  • CVE-2002-0666Nov 4, 2002
    risk 0.00cvss epss 0.02

    IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in…

  • CVE-2000-1183Jan 9, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.

  • CVE-1999-1435Jul 10, 1998
    risk 0.00cvss epss 0.00

    Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.

  • CVE-1999-0010Apr 8, 1998
    risk 0.00cvss epss 0.02

    Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

  • CVE-1999-0024Aug 13, 1997
    risk 0.00cvss epss 0.05

    DNS cache poisoning via BIND, by predictable query IDs.

  • CVE-1999-0868Feb 20, 1997
    risk 0.00cvss epss 0.01

    ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.

  • CVE-1999-0048Jan 27, 1997
    risk 0.00cvss epss 0.03

    Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.

  • CVE-1999-0138Jun 26, 1996
    risk 0.00cvss epss 0.01

    The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

  • CVE-1999-0078Apr 18, 1996
    risk 0.00cvss epss 0.01

    pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

Page 3 of 3