Filtered by vendor Flexense
Subscribe
Total
28 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-15220 | 1 Flexense | 1 Vx Search | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to execute arbitrary code. | |||||
CVE-2017-15663 | 1 Flexense | 1 Disk Pulse | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120. | |||||
CVE-2018-5262 | 1 Flexense | 1 Diskboss | 2024-02-04 | 10.0 HIGH | 9.8 CRITICAL |
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account. | |||||
CVE-2017-15662 | 1 Flexense | 1 Vx Search | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123. | |||||
CVE-2017-15950 | 1 Flexense | 1 Syncbreeze | 2024-02-04 | 6.8 MEDIUM | 7.8 HIGH |
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode. | |||||
CVE-2017-15665 | 1 Flexense | 1 Diskboss | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094. | |||||
CVE-2017-7310 | 1 Flexense | 3 Diskboss, Disksorter, Syncbreeze | 2024-02-04 | 6.8 MEDIUM | 7.8 HIGH |
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element. | |||||
CVE-2017-6416 | 1 Flexense | 1 Sysgauge | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string. |