Open Source Security Information Management
Alienvault · 22 CVEs
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
Jan 27, 2020
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
Mar 14, 2018
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary com…
May 23, 2017
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges…
May 23, 2017
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL…
Aug 21, 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via…
Aug 21, 2014
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to…
Aug 21, 2014
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0…
Aug 21, 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a craf…
Jun 18, 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a cr…
Jun 18, 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and exec…
Jun 18, 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via…
Jun 13, 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via…
Jun 13, 2014
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlie…
Oct 9, 2013
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remo…
Aug 20, 2013
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) b…
Aug 15, 2013
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3…
Jul 3, 2012
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (O…
Jul 3, 2012
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Mana…
Dec 21, 2009
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Informatio…
Dec 21, 2009
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Infor…
Dec 21, 2009
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allow…
Dec 21, 2009
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2013-6056 | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability | HIGH | 1.71% | Jan 27, 2020 |
| CVE-2018-7279 | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1. | CRITICAL | 2.44% | Mar 14, 2018 |
| CVE-2015-4046 | The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to… | HIGH | 2.71% | May 23, 2017 |
| CVE-2015-4045 | The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script. | MEDIUM | 0.51% | May 23, 2017 |
| CVE-2014-5383 | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | MEDIUM | 21.19% | Aug 21, 2014 |
| CVE-2014-5210 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_lic… | HIGH | 14.92% | Aug 21, 2014 |
| CVE-2014-5159 | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the w… | HIGH | 1.26% | Aug 21, 2014 |
| CVE-2014-5158 | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbit… | HIGH | 3.68% | Aug 21, 2014 |
| CVE-2014-4153 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request. | HIGH | 7.38% | Jun 18, 2014 |
| CVE-2014-4152 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to in… | HIGH | 5.79% | Jun 18, 2014 |
| CVE-2014-4151 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_fil… | HIGH | 7.32% | Jun 18, 2014 |
| CVE-2014-3805 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_l… | HIGH | 13.07% | Jun 13, 2014 |
| CVE-2014-3804 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_… | HIGH | 72.38% | Jun 13, 2014 |
| CVE-2013-5967 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbi… | HIGH | 19.02% | Oct 9, 2013 |
| CVE-2013-5321 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL co… | HIGH | 1.37% | Aug 20, 2013 |
| CVE-2013-5300 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to in… | MEDIUM | 1.78% | Aug 15, 2013 |
| CVE-2012-3835 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbi… | MEDIUM | 2.23% | Jul 3, 2012 |
| CVE-2012-3834 | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated us… | MEDIUM | 1.44% | Jul 3, 2012 |
| CVE-2009-4375 | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other… | HIGH | 0.97% | Dec 21, 2009 |
| CVE-2009-4374 | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly… | HIGH | 1.64% | Dec 21, 2009 |
| CVE-2009-4373 | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and pos… | HIGH | 2.98% | Dec 21, 2009 |
| CVE-2009-4372 | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary… | HIGH | 4.82% | Dec 21, 2009 |
Showing 1 to 22 of 22 CVEs