Show filters
93 Total Results
Displaying 71-80 of 93
Sort by:
Attacker Value
Unknown

CVE-2018-1141

Disclosure Date: March 20, 2018 (last updated November 26, 2024)
When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location.
0
Attacker Value
Unknown

CVE-2017-18214

Disclosure Date: March 04, 2018 (last updated November 26, 2024)
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
Attacker Value
Unknown

CVE-2017-11506

Disclosure Date: August 09, 2017 (last updated November 26, 2024)
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
0
Attacker Value
Unknown

CVE-2017-2122

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-7850

Disclosure Date: April 19, 2017 (last updated November 26, 2024)
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
0
Attacker Value
Unknown

CVE-2017-7849

Disclosure Date: April 19, 2017 (last updated November 26, 2024)
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
0
Attacker Value
Unknown

CVE-2017-7199

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
0
Attacker Value
Unknown

CVE-2017-6543

Disclosure Date: March 08, 2017 (last updated November 26, 2024)
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installations on Windows.
0
Attacker Value
Unknown

CVE-2016-9259

Disclosure Date: February 28, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-9260

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
0