VYPR

Vendor CVEs

Securecomputing

All CVEs

66 total · sorted by risk
  • CVE-2020-29023LowFeb 16, 2021
    risk 0.23cvss 3.5epss 0.01

    Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects:…

  • CVE-2020-29021LowFeb 8, 2021
    risk 0.23cvss 3.5epss 0.01

    A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3.

  • CVE-2022-38125LowApr 19, 2023
    risk 0.19cvss 2.9epss 0.00

    Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.

  • CVE-2004-0112Nov 23, 2004
    risk 0.01cvss —epss 0.10

    The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake…

  • CVE-2004-0081Nov 23, 2004
    risk 0.01cvss —epss 0.07

    OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

  • CVE-2007-3985Jul 25, 2007
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to download arbitrary files via a .. (dot dot) in the name parameter.

  • CVE-2007-3986Jul 25, 2007
    risk 0.00cvss —epss 0.02

    file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE:…

  • CVE-2006-5303Oct 17, 2006
    risk 0.00cvss —epss 0.00

    Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in…

  • CVE-2006-4613Sep 7, 2006
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and (2) the use of vulnerable versions of ClamAV before 0.88.4. NOTE: it is possible that vector 2 is…

  • CVE-2005-0864May 2, 2005
    risk 0.00cvss —epss 0.02

    The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.

  • CVE-2005-0865May 2, 2005
    risk 0.00cvss —epss 0.02

    Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.

  • CVE-2004-2545Dec 31, 2004
    risk 0.00cvss —epss 0.02

    Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system…

  • CVE-2004-2543Dec 31, 2004
    risk 0.00cvss —epss 0.02

    Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because…

  • CVE-2004-2399Dec 31, 2004
    risk 0.00cvss —epss 0.01

    Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (CPU consumption) via delayed responses to DNS queries.

  • CVE-2004-2544Dec 31, 2004
    risk 0.00cvss —epss 0.00

    Admin Console in Secure Computing Corporation Sidewinder G2 6.1.0.01 exports private keys when exporting firewall certificates, which might allow attackers to obtain sensitive information.

  • CVE-2004-1970Apr 26, 2004
    risk 0.00cvss —epss 0.01

    Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the…

Page 2 of 2