Skip to main content

Vendor archive

nessus CVEs

Beta · best-effort

13 CVEs tagged to vendor nessus2 Critical, 2 High, 5 Medium, 4 Low, 0 Unrated.

CVE-2010-2989

Published Aug 10, 2010

nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2914

Published Jul 30, 2010

Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4061

Published Jul 30, 2007

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot d…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4062

Published Jul 30, 2007

The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4031

Published Jul 27, 2007

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the ar…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3546

Published Jul 3, 2007

Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2093

Published Apr 29, 2006

Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1445

Published Dec 31, 2004

A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2722

Published Dec 31, 2004

Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has d…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2723

Published Dec 31, 2004

NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0372

Published Jun 16, 2003

Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbit…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0373

Published Jun 16, 2003

Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0374

Published Jun 16, 2003

Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1