
CVE-2010-2989
https://notcve.org/view.php?id=CVE-2010-2989
09 Aug 2010 — nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response. nessusd_www_server.nbin en el plugin Nessus Web Server v1.2.4 para Nessus permite a atacantes remotos obtener información sensible a través de una petición al método /feed, que revela la versión en una respuesta. • http://www.securityfocus.com/archive/1/512645/100/0/threaded • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2010-2914
https://notcve.org/view.php?id=CVE-2010-2914
30 Jul 2010 — Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en nessusd_www_server.nbin del complemento Nessus Web Server v1.2.4 de Nessus. Permite a atacantes remotos inyectar codigo de script web o código HTML a través de vectores de ataque sin especificar. • http://secunia.com/advisories/40722 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2007-3546
https://notcve.org/view.php?id=CVE-2007-3546
03 Jul 2007 — Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la interfaz gráfica para Windows de Nessus Vulnerability Scanner anterior a 3.0.6 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados. • http://osvdb.org/37011 •

CVE-2006-2093
https://notcve.org/view.php?id=CVE-2006-2093
29 Apr 2006 — Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script "can not do anything nasty." This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory. • http://securityreason.com/securityalert/817 • CWE-399: Resource Management Errors •

CVE-2004-2722
https://notcve.org/view.php?id=CVE-2004-2722
31 Dec 2004 — Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue • http://archives.neohapsis.com/archives/fulldisclosure/2004-03/1363.html • CWE-255: Credentials Management Errors •

CVE-2004-1445
https://notcve.org/view.php?id=CVE-2004-1445
31 Dec 2004 — A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges. • http://secunia.com/advisories/12127 •

CVE-2003-0372 – Nessus 2.0.x - LibNASL Arbitrary Code Execution
https://notcve.org/view.php?id=CVE-2003-0372
06 Jun 2003 — Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script. Vulnerabilidad de entero con signo en libnsl en Nessus anterior a la 2.0.6 permite que usuarios locales con privilegios de carga de plugin provoquen una denegación de servicio (core dump) y posiblemente ejecuten código arbitrari... • https://www.exploit-db.com/exploits/22634 • CWE-189: Numeric Errors •

CVE-2003-0373
https://notcve.org/view.php?id=CVE-2003-0373
06 Jun 2003 — Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function. Múltiples desbordamientos de búfer en Nessus anterior a la 2.0.6 permiten que usuarios locales con privilegios de carga de plugin provoquen una denegación de... • http://marc.info/?l=bugtraq&m=105364059803427&w=2 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2003-0374
https://notcve.org/view.php?id=CVE-2003-0374
06 Jun 2003 — Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus." Múltiples vulnerabilidades desconocidas en Nessus anterior a la 2.0.6, en libnessus y posiblemente libnsl (un conjunto diferente de las señaladas en CAN-2003-0372 y CAN-2003-0373). • http://marc.info/?l=bugtraq&m=105364059803427&w=2 •