Vdgsecurity maintains a focused product line centered on VDG Sense, a security appliance serving a specialized but prominent niche in the vulnerability landscape. The vendor's disclosures cluster around access-control and input-handling weaknesses including improper authentication, path traversal, sensitive-information exposure, and memory-safety issues characteristic of appliance firmware. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vdgsecurity over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9451HIGH Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote attackers to execute arbitrary code via th | Jan 2, 2015 | 7.5 | 21 | NO | NO |
CVE-2014-9575MEDIUM VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (col | Jan 8, 2015 | 6.4 | 18 | NO | NO |
CVE-2014-9452MEDIUM Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI to images/. | Jan 2, 2015 | 5.0 | 16 | NO | NO |
CVE-2014-9579MEDIUM VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by reading the plugin configuration | Jan 8, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-9578MEDIUM VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowl | Jan 8, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-9576MEDIUM VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgres and (3) NTP Windows user acco | Jan 8, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-9577MEDIUM VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in | Jan 8, 2015 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vdgsecurity.
Media articles that mention a CVE ID that affects a product developed by Vdgsecurity — matched by CVE ID, not by vendor name.