📦

tarantella_enterprise

Vendor: tarantella

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 1 Remote Access
Total CVEs 16 Total Indexed
Avg. EPSS 5.90% Exploit Prob.
Latest CVE CVE-2018-19754 Dec 05

Security Vulnerability Index

Page 1 / 2
8.8 CVSS

Tarantella Enterprise before 3.11 allows bypassing Access Control.

EPSS: 2.62%
7.5 CVSS

Tarantella Enterprise before 3.11 allows Directory Traversal.

EPSS: 16.56%
5.0 CVSS

Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.

EPSS: 1.26%
5.0 CVSS

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

EPSS: 7.23%
7.5 CVSS

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

EPSS: 9.54%
5.0 CVSS

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

EPSS: 10.42%
1.2 CVSS
CVE-2002-0296
Exploit Found

The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

EPSS: 0.66%
5.0 CVSS

ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.

EPSS: 1.88%
6.2 CVSS
CVE-2002-0211
RCE Exploit Found

Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

EPSS: 0.89%
5.0 CVSS
CVE-2001-0805
Exploit Found

Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter.

EPSS: 7.94%