Home/Product/alienvault open source security information management
Product

alienvault open source security information management

24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2013-6056
< 4.3.3.1
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
7.5HIGH
CVE-2018-7279
< 5.5.1
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
9.8CRITICAL
CVE-2015-4046
<= 5.0
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via t
7.2HIGH
CVE-2015-4045
<= 5.0
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a craft
6.7MEDIUM
CVE-2014-5383
<= 4.6.1
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands v
CVE-2014-5210
<= 4.6.1
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (
CVE-2014-5159
<= 4.5
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arb
CVE-2014-5158
<= 4.5
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remo
CVE-2014-4153
<= 4.7.0
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_fil
CVE-2014-4152
<= 4.7.0
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remot
CVE-2014-4151
<= 4.7.0
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitra
CVE-2014-3805
<= 4.6.1
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (
CVE-2014-3804
<= 4.6.1
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (
CVE-2013-5967
<= 4.3
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow rem
CVE-2013-5321
all versions
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attacker
CVE-2013-5300
<= 4.2.3
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0
CVE-2012-3835
all versions
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow re
CVE-2012-3834
all versions
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 a
CVE-2009-4375
all versions
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSS
CVE-2009-4374
<= 2.1.5
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Managemen
CVE-2009-4373
all versions
Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Mana
CVE-2009-4372
all versions
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote at
CVE-2008-0920
<= 0.9.9
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows rem
CVE-2008-0919
all versions
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and
threatengine.sh