CVE-2018-20799
- EPSS 1.59%
- Veröffentlicht 01.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:12
In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), w...
CVE-2018-20798
- EPSS 1.42%
- Veröffentlicht 01.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:12
The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.
CVE-2018-4021
- EPSS 72.21%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:31
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An ...
CVE-2018-4020
- EPSS 48.72%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:31
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An ...
CVE-2018-4019
- EPSS 48.72%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:31
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An ...
- EPSS 11.19%
- Veröffentlicht 26.09.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:00
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents...
CVE-2017-1000479
- EPSS 32.77%
- Veröffentlicht 03.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:49
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-REL...
CVE-2015-6511
- EPSS 2.05%
- Veröffentlicht 18.08.2015 15:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the server[] parameter to services_ntpd.php.
CVE-2015-6510
- EPSS 2.05%
- Veröffentlicht 18.08.2015 15:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) srctrack, (2) use_mfs_tmp_size, or (3) use_mfs_var_size parameter to system_advanced_misc.php; the (...
CVE-2015-6509
- EPSS 2.05%
- Veröffentlicht 18.08.2015 15:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) proxypass parameter to system_advanced_misc.php; (2) adaptiveend, (3) adaptivestart, (4) maximumstat...