Show filters
154 Total Results
Displaying 141-150 of 154
Sort by:
Attacker Value
Unknown

CVE-2017-7850

Disclosure Date: April 19, 2017 (last updated November 26, 2024)
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
0
Attacker Value
Unknown

CVE-2017-7849

Disclosure Date: April 19, 2017 (last updated November 26, 2024)
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
0
Attacker Value
Unknown

CVE-2017-7199

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
0
Attacker Value
Unknown

CVE-2017-6543

Disclosure Date: March 08, 2017 (last updated November 26, 2024)
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installations on Windows.
0
Attacker Value
Unknown

CVE-2016-9259

Disclosure Date: February 28, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-9261

Disclosure Date: February 28, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2016-9260

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
0
Attacker Value
Unknown

CVE-2016-4055

Disclosure Date: January 23, 2017 (last updated November 08, 2023)
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
Attacker Value
Unknown

CVE-2017-5179

Disclosure Date: January 05, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4448

Disclosure Date: June 09, 2016 (last updated November 25, 2024)
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.