Page 37 of 188 results (0.003 seconds)

CVSS: 7.8EPSS: 1%CPEs: 3EXPL: 0

SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow. • http://securityreason.com/securityalert/3291 http://www.securityfocus.com/archive/1/319712 http://www.securityfocus.com/bid/7435 https://exchange.xforce.ibmcloud.com/vulnerabilities/11876 • CWE-20: Improper Input Validation •

CVSS: 5.1EPSS: 0%CPEs: 1EXPL: 0

SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload. • http://www.kb.cert.org/vuls/id/287771 http://www.kb.cert.org/vuls/id/AAMN-5L74VD • CWE-399: Resource Management Errors •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name. • http://www.iss.net/security_center/static/10531.php http://www.securityfocus.com/archive/1/297692 http://www.securityfocus.com/bid/6063 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML via a blocked URL. • https://www.exploit-db.com/exploits/21453 http://online.securityfocus.com/archive/1/272935 http://www.iss.net/security_center/static/9103.php http://www.securityfocus.com/bid/4755 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 1

SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. • https://www.exploit-db.com/exploits/19522 http://www.securityfocus.com/archive/1/199632 http://www.securityfocus.com/bid/3098 •