Vulnerabilities (CVE)

Filtered by vendor Flexense Subscribe
Total 28 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15220 1 Flexense 1 Vx Search 2024-02-04 7.5 HIGH 9.8 CRITICAL
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to execute arbitrary code.
CVE-2017-15663 1 Flexense 1 Disk Pulse 2024-02-04 5.0 MEDIUM 7.5 HIGH
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
CVE-2018-5262 1 Flexense 1 Diskboss 2024-02-04 10.0 HIGH 9.8 CRITICAL
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.
CVE-2017-15662 1 Flexense 1 Vx Search 2024-02-04 5.0 MEDIUM 7.5 HIGH
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123.
CVE-2017-15950 1 Flexense 1 Syncbreeze 2024-02-04 6.8 MEDIUM 7.8 HIGH
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode.
CVE-2017-15665 1 Flexense 1 Diskboss 2024-02-04 5.0 MEDIUM 7.5 HIGH
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
CVE-2017-7310 1 Flexense 3 Diskboss, Disksorter, Syncbreeze 2024-02-04 6.8 MEDIUM 7.8 HIGH
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.
CVE-2017-6416 1 Flexense 1 Sysgauge 2024-02-04 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.