Vulnerabilities (CVE)

Filtered by vendor Solarwinds Subscribe
Total 296 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47012 1 Solarwinds 1 Dynamips 2025-04-03 N/A 7.5 HIGH
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
CVE-2004-0330 1 Solarwinds 1 Serv-u File Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.
CVE-2002-1209 1 Solarwinds 1 Tftp Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
CVE-2002-2393 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.
CVE-2005-3467 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.
CVE-2004-2533 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.
CVE-2001-1463 1 Solarwinds 1 Serv-u File Server 2025-04-03 7.5 HIGH N/A
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
CVE-2002-1542 1 Solarwinds 1 Tftp Server 2025-04-03 5.0 MEDIUM N/A
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
CVE-2004-1675 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
CVE-2001-0054 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
CVE-2004-1852 1 Solarwinds 1 Dameware Mini Remote Control 2025-04-03 5.0 MEDIUM N/A
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
CVE-2004-2532 1 Solarwinds 1 Serv-u File Server 2025-04-03 10.0 HIGH N/A
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.
CVE-2006-1951 1 Solarwinds 1 Tftp Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.
CVE-2004-1992 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
CVE-2004-2111 1 Solarwinds 1 Serv-u File Server 2025-04-03 8.5 HIGH N/A
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
CVE-2024-28989 1 Solarwinds 1 Web Help Desk 2025-02-25 N/A 5.5 MEDIUM
SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.
CVE-2024-52606 1 Solarwinds 1 Solarwinds Platform 2025-02-25 N/A 3.5 LOW
SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request.
CVE-2024-52611 1 Solarwinds 1 Solarwinds Platform 2025-02-25 N/A 3.5 LOW
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions.
CVE-2024-52612 1 Solarwinds 1 Solarwinds Platform 2025-02-25 N/A 6.8 MEDIUM
SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by a high- privileged account to be exploitable.
CVE-2024-45709 1 Solarwinds 1 Web Help Desk 2025-02-25 N/A 5.3 MEDIUM
SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.