CVE-2007-6385
https://notcve.org/view.php?id=CVE-2007-6385
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries. El servidor proxy en Kerio WinRoute Firewall anterior a 6.4.1 no hace cumplir la autenticación para páginas HTTPS, lo cual tiene impacto y vectores de ataque desconocidos. NOTA: no está claro si este asunto atraviesa fronteras de privilegios. • http://osvdb.org/42122 http://secunia.com/advisories/28072 http://www.kerio.com/kwf_history.html http://www.securityfocus.com/bid/26851 http://www.securitytracker.com/id?1019095 http://www.vupen.com/english/advisories/2007/4212 https://exchange.xforce.ibmcloud.com/vulnerabilities/39020 • CWE-287: Improper Authentication •
CVE-2006-5420
https://notcve.org/view.php?id=CVE-2006-5420
Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses. Kerio WinRoute Firewall 6.2.2 y anteriores permite a un atacante remoto provocar denegación de servicio (caida) a través de respuestas DNS mal formadas. • http://secunia.com/advisories/22986 http://securitytracker.com/id?1017067 http://www.kerio.com/kwf_history.html http://www.securityfocus.com/bid/20584 http://www.vupen.com/english/advisories/2006/4056 https://exchange.xforce.ibmcloud.com/vulnerabilities/29629 •