Vulnerabilities > Tenable

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-4055 Resource Exhaustion vulnerability in multiple products
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
network
low complexity
momentjs tenable oracle CWE-400
6.5
2017-01-05 CVE-2017-5179 Cross-site Scripting vulnerability in Tenable Nessus
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
tenable CWE-79
3.5
2016-06-09 CVE-2016-4448 Use of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
network
low complexity
hp apple xmlsoft redhat slackware oracle tenable mcafee CWE-134
critical
9.8
2014-10-21 CVE-2014-7280 Cross-Site Scripting vulnerability in Tenable web UI 2.3.3
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
network
tenable CWE-79
4.3
2014-07-23 CVE-2014-4980 Information Exposure vulnerability in Tenable Nessus and web UI
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
network
low complexity
tenable CWE-200
5.0
2014-04-11 CVE-2014-2848 Race Condition vulnerability in Tenable Nessus and Plugin-Set
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.
6.9
2013-09-24 CVE-2013-5911 Cross-Site Scripting vulnerability in Tenable Securitycenter 4.6/4.7
Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
network
tenable CWE-79
4.3