openvas openvas_manager CVE Vulnerabilities (5)

CVEs: 5 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting openvas openvas_manager (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2011-1597 OpenVAS Manager v2.0.3 allows plugin remote code execution. [email protected] 8.8 1.77% 2020-02-06 2024-11-21
CVE-2014-9220 SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command. [email protected] 7.5 0.44% 2014-12-03 2026-05-06
CVE-2013-6765 OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c. [email protected] 7.5 4.54% 2014-05-19 2026-05-06
CVE-2012-5520 The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number field in an OMP request. [email protected] 7.5 2.13% 2012-11-26 2026-04-29
CVE-2011-0018 The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA). [email protected] 9.0 11.69% 2011-01-28 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence