Vulnerabilities > Quest > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-31 CVE-2018-11132 OS Command Injection vulnerability in Quest Kace System Management Appliance 8.0.318
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed.
network
low complexity
quest CWE-78
8.8
2018-02-08 CVE-2018-1162 Unspecified vulnerability in Quest Netvault Backup 11.2.0.13
This vulnerability allows remote attackers to create a denial-of-service condition on vulnerable installations of Quest NetVault Backup 11.2.0.13.
network
low complexity
quest
8.1
2017-04-14 CVE-2017-6554 Improper Input Validation vulnerability in Quest Privilege Manager 6.0.027/6.0.050
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.
network
low complexity
quest CWE-20
7.2