Hd Moore

#1003de 53,635
208.1CVSS total
Vulnerabilidades · 24
Média
3
Alta
18
Crítica
3
PT-2015-2867
9.8
2015-12-18
Juniper Networks · Screenos · CVE-2015-7755
**Name of the Vulnerable Software and Affected Versions** Juniper ScreenOS versions 6.2.0r15 through 6.2.0r18 Juniper ScreenOS versions 6.3.0r12 before 6.3.0r12b Juniper ScreenOS versions 6.3.0r13 before 6.3.0r13b Juniper ScreenOS versions 6.3.0r14 before 6.3.0r14b Juniper ScreenOS versions 6.3.0r15 before 6.3.0r15b Juniper ScreenOS versions 6.3.0r16 before 6.3.0r16b Juniper ScreenOS versions 6.3.0r17 before 6.3.0r17b Juniper ScreenOS versions 6.3.0r18 before 6.3.0r18b Juniper ScreenOS versions 6.3.0r19 before 6.3.0r19b Juniper ScreenOS versions 6.3.0r20 before 6.3.0r21 **Description** The issue is related to weaknesses in the authentication procedure of the ScreenOS operating system. This allows a remote attacker to gain administrative access by entering a specially crafted password during an SSH or TELNET session. **Recommendations** For Juniper ScreenOS versions 6.2.0r15 through 6.2.0r18, update to a version outside of this range. For Juniper ScreenOS versions 6.3.0r12 before 6.3.0r12b, update to 6.3.0r12b or later. For Juniper ScreenOS versions 6.3.0r13 before 6.3.0r13b, update to 6.3.0r13b or later. For Juniper ScreenOS versions 6.3.0r14 before 6.3.0r14b, update to 6.3.0r14b or later. For Juniper ScreenOS versions 6.3.0r15 before 6.3.0r15b, update to 6.3.0r15b or later. For Juniper ScreenOS versions 6.3.0r16 before 6.3.0r16b, update to 6.3.0r16b or later. For Juniper ScreenOS versions 6.3.0r17 before 6.3.0r17b, update to 6.3.0r17b or later. For Juniper ScreenOS versions 6.3.0r18 before 6.3.0r18b, update to 6.3.0r18b or later. For Juniper ScreenOS versions 6.3.0r19 before 6.3.0r19b, update to 6.3.0r19b or later. For Juniper ScreenOS versions 6.3.0r20 before 6.3.0r21, update to 6.3.0r21 or later. As a temporary workaround, consider restricting access to SSH and TELNET sessions until a patch is available.
PT-2010-4592
9.3
2010-08-27
Microsoft · Windows Vista · CVE-2010-3147
**Name of the Vulnerable Software and Affected Versions** Windows Address Book version 6.00.2900.5512 in Microsoft Windows XP SP2 and SP3 Windows Address Book in Windows Server 2003 SP2 Windows Address Book in Windows Vista SP1 and SP2 Windows Address Book in Windows Server 2008 Gold, SP2, and R2 Windows Address Book in Windows 7 **Description** The issue allows local users to gain privileges via a Trojan horse `wab32res.dll` file in the current working directory. This can occur in directories containing Windows Address Book (WAB), VCF (aka vCard), or P7C files. A remote code execution vulnerability exists in the way Windows Address Book handles the loading of DLL files, potentially allowing an attacker to take complete control of an affected system, install programs, view, change, or delete data, or create new accounts with full user rights. **Recommendations** For Windows XP SP2 and SP3, consider disabling the `wab.exe` until a patch is available. For Windows Server 2003 SP2, restrict access to the Windows Address Book to minimize the risk of exploitation. For Windows Vista SP1 and SP2, avoid using the Windows Address Book in directories that may contain malicious `wab32res.dll` files. For Windows Server 2008 Gold, SP2, and R2, and Windows 7, apply configuration changes to prevent the loading of untrusted DLL files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.