CVE-2013-6056
- EPSS 0.4%
- Published 27.01.2020 15:15:11
- Last modified 21.11.2024 01:58:42
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
CVE-2018-7279
- EPSS 2.4%
- Published 14.03.2018 13:29:00
- Last modified 21.11.2024 04:11:55
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
CVE-2015-4046
- EPSS 6.2%
- Published 23.05.2017 04:29:00
- Last modified 20.04.2025 01:37:25
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
CVE-2015-4045
- EPSS 0.06%
- Published 23.05.2017 04:29:00
- Last modified 20.04.2025 01:37:25
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.
CVE-2014-5383
- EPSS 23.46%
- Published 21.08.2014 14:55:05
- Last modified 12.04.2025 10:46:40
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
- EPSS 13.51%
- Published 21.08.2014 14:55:05
- Last modified 12.04.2025 10:46:40
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
CVE-2014-5159
- EPSS 0.37%
- Published 21.08.2014 14:55:05
- Last modified 12.04.2025 10:46:40
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.
- EPSS 5.49%
- Published 21.08.2014 14:55:05
- Last modified 12.04.2025 10:46:40
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
- EPSS 11.38%
- Published 18.06.2014 19:55:06
- Last modified 12.04.2025 10:46:40
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.
CVE-2014-4153
- EPSS 7.56%
- Published 18.06.2014 19:55:06
- Last modified 12.04.2025 10:46:40
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.