Vulnerabilities > Tenable > Nessus > 8.3.2

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-3982 Improper Input Validation vulnerability in Tenable Nessus
Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types.
network
low complexity
tenable CWE-20
4.0
2019-08-15 CVE-2019-3974 Unspecified vulnerability in Tenable Nessus
Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially creating a denial of service condition.
network
low complexity
tenable microsoft
8.5
2019-07-01 CVE-2019-3962 Cross-site Scripting vulnerability in Tenable Nessus
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages.
network
tenable CWE-79
4.3
2019-06-25 CVE-2019-3961 Cross-site Scripting vulnerability in Tenable Nessus
Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input.
network
tenable CWE-79
4.3
2019-06-24 CVE-2018-20843 XXE vulnerability in multiple products
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
7.5