CVE-2017-11177
https://notcve.org/view.php?id=CVE-2017-11177
TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory. TRITON AP-EMAIL 8.2 anterior a la versión 8.2 IB no restringe correctamente el acceso a archivos en un directorio sin especificar. • https://support.forcepoint.com/KBArticle?id=000014490 • CWE-20: Improper Input Validation •
CVE-2015-5718 – Websense Triton Content Manager 8.0.0 Build 1165 Buffer Overflow
https://notcve.org/view.php?id=CVE-2015-5718
Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a crafted diagnostic command line request to submit_net_debug.cgi. Desbordamiento del buffer basado en pila en la función handle_debug_network en el gestor en Websense Content Gateway en versiones anteriores a la 8.0.0 HF02, permite a administradores remotos provocar una denegación de servicio (caída) a través de una petición de diagnóstico de línea de comando manipulada a submit_net_debug.cgi. Websense Triton Content Manager version 8.0.0 build 1165 suffers from a stack buffer overflow vulnerability in handle_debug_network. • http://packetstormsecurity.com/files/132968/Websense-Triton-Content-Manager-8.0.0-Build-1165-Buffer-Overflow.html http://seclists.org/fulldisclosure/2015/Aug/8 http://www.securityfocus.com/archive/1/536138/100/0/threaded http://www.securitytracker.com/id/1033263 http://www.websense.com/support/article/kbarticle/v8-0-0-About-Hotfix-02-for-Websense-Content-Gateway https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150805-0_Websense_Content_Gateway_stack_buffer_overflow_in_handle_ • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-2770
https://notcve.org/view.php?id=CVE-2015-2770
Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de CSRF en la página de líneas de comandos en los dispositivos de la serie V de Websense TRITON anterior a 8.0.0 permite a atacantes remotos secuestrar la autenticación de victimas no especificadas a través de vectores desconocidos. • http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2015-2765
https://notcve.org/view.php?id=CVE-2015-2765
The Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 allows remote attackers to conduct clickjacking attacks via unspecified vectors. Email Security Gateway en Websense TRITON AP-EMAIL anterior a 8.0.0 permite a atacantes remotos realizar ataques de clickjacking a través de vectores no especificados. • http://www.securityfocus.com/bid/73427 http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 • CWE-20: Improper Input Validation •
CVE-2015-2771
https://notcve.org/view.php?id=CVE-2015-2771
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors. Mail Server en Websense TRITON AP-EMAIL y dispositivos de la serie V anterior a 8.0.0 utiliza credenciales de texto plano, lo que permite a atacantes remotos obtener información sensible a través de vectores no especificados. • http://www.securityfocus.com/bid/73428 http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •