MidnightBSD

Advisories for bluecoat

CVE-2002-1060 MEDIUM

Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat cacheos 4.0.12
bluecoat cacheos 4.0.11
bluecoat cacheos 3.1.21
bluecoat cacheos 4.1.6
bluecoat cacheos 4.0.13
bluecoat cacheos 3.1.18
bluecoat cacheos 3.1.17
bluecoat cacheos 4.0
bluecoat cacheos 3.1.19
bluecoat cacheos 4.0.14
CVE-2004-0079 MEDIUM

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-476,CWE-476,

Products Affected

Vendor Product Version
avaya s8500 r2.0.1
bluecoat cacheos_ca_sa 4.1.12
openssl openssl 0.9.7b
checkpoint firewall-1 2.0
stonesoft stonegate 1.6.2
cisco pix_firewall_software 6.0(4.101)
cisco css11000_content_services_switch *
avaya vsu 500
openssl openssl 0.9.6i
stonesoft stonegate 2.0.4
bluecoat proxysg *
stonesoft stonebeat_webcluster 2.0
cisco css_secure_content_accelerator 1.0
cisco ciscoworks_common_services 2.2
redhat linux 7.3
neoteris instant_virtual_extranet 3.1
openbsd openbsd 3.4
stonesoft stonebeat_fullcluster 1_2.0
openssl openssl 0.9.6g
tarantella tarantella_enterprise 3.20
stonesoft stonegate 2.0.7
lite speed_technologies_litespeed_web_server 1.3
redhat linux 7.2
avaya vsu 5
4d webstar 5.2.3
cisco access_registrar *
hp hp-ux 11.00
avaya s8700 r2.0.1
checkpoint vpn-1 next_generation_fp2
avaya sg5 4.2
cisco pix_firewall_software 6.0(3)
cisco pix_firewall_software 6.0(4)
lite speed_technologies_litespeed_web_server 1.3_rc3
avaya s8300 r2.0.0
cisco pix_firewall_software 6.3
cisco pix_firewall 6.2.2_.111
avaya vsu 5x
cisco pix_firewall_software 6.3(3.102)
stonesoft stonebeat_fullcluster 2.0
stonesoft stonegate 2.0.9
avaya s8300 r2.0.1
cisco webns 6.10_b4
stonesoft stonegate 2.0.6
cisco ios 12.1(13)e9
stonesoft stonebeat_securitycluster 2.0
avaya sg5 4.4
cisco pix_firewall_software 6.3(2)
lite speed_technologies_litespeed_web_server 1.2.2
lite speed_technologies_litespeed_web_server 1.3_rc2
stonesoft stonegate 1.7.1
cisco pix_firewall_software 6.1(2)
freebsd freebsd 5.2.1
hp hp-ux 8.05
securecomputing sidewinder 5.2.0.02
securecomputing sidewinder 5.2.1.02
stonesoft stonebeat_webcluster 2.5
openssl openssl 0.9.6c
lite speed_technologies_litespeed_web_server 1.2.1
4d webstar 5.2
freebsd freebsd 4.8
neoteris instant_virtual_extranet 3.3
sgi propack 3.0
stonesoft stonegate_vpn_client 1.7
cisco ios 12.1(19)e1
cisco ios 12.2za
novell edirectory 8.6.2
novell edirectory 8.7.1
hp wbem a.02.00.00
openbsd openbsd 3.3
stonesoft stonebeat_fullcluster 1_3.0
cisco firewall_services_module 1.1_(3.005)
avaya sg5 4.3
stonesoft stonegate_vpn_client 1.7.2
redhat linux 8.0
checkpoint firewall-1 next_generation_fp1
stonesoft stonegate 1.7.2
securecomputing sidewinder 5.2.0.01
lite speed_technologies_litespeed_web_server 1.0.3
hp apache-based_web_server 2.0.43.00
checkpoint vpn-1 next_generation_fp0
stonesoft stonegate 2.0.1
avaya intuity_audix *
cisco pix_firewall_software 6.0(2)
stonesoft stonegate_vpn_client 2.0
stonesoft stonegate 1.7
openssl openssl 0.9.7a
freebsd freebsd 4.9
dell bsafe_ssl-j 3.0
apple mac_os_x 10.3.3
securecomputing sidewinder 5.2.0.04
avaya intuity_audix 5.1.46
cisco webns 6.10
hp hp-ux 11.11
cisco ios 12.2sy
cisco firewall_services_module 2.1_(0.208)
securecomputing sidewinder 5.2.1
cisco webns 7.2_0.0.03
securecomputing sidewinder 5.2.0.03
stonesoft stonegate 2.2.4
hp wbem a.01.05.08
vmware gsx_server 2.5.1_build_5336
cisco firewall_services_module *
neoteris instant_virtual_extranet 3.3.1
vmware gsx_server 3.0_build_7592
4d webstar 4.0
sgi propack 2.4
vmware gsx_server 2.0
cisco pix_firewall_software 6.2(3)
openssl openssl 0.9.6f
cisco pix_firewall_software 6.1(3)
stonesoft stonegate_vpn_client 2.0.8
stonesoft stonegate 2.0.8
tarantella tarantella_enterprise 3.30
dell bsafe_ssl-j 3.0.1
cisco okena_stormwatch 3.2
neoteris instant_virtual_extranet 3.0
hp wbem a.02.00.01
vmware gsx_server 2.0.1_build_2129
cisco ios 12.2(14)sy1
openssl openssl 0.9.6k
redhat openssl 0.9.7a-2
novell edirectory 8.5
cisco gss_4490_global_site_selector *
apple mac_os_x_server 10.3.3
lite speed_technologies_litespeed_web_server 1.3_rc1
lite speed_technologies_litespeed_web_server 1.3.1
cisco ios 12.2(14)sy
cisco webns 7.1_0.1.02
lite speed_technologies_litespeed_web_server 1.1
cisco pix_firewall_software 6.1
sco openserver 5.0.7
dell bsafe_ssl-j 3.1
stonesoft stonegate 2.0.5
stonesoft stonegate 1.6.3
checkpoint firewall-1 next_generation_fp2
stonesoft stonegate 1.5.17
cisco css_secure_content_accelerator 2.0
cisco gss_4480_global_site_selector *
cisco webns 7.10
freebsd freebsd 5.1
avaya intuity_audix s3210
novell imanager 1.5
cisco pix_firewall_software 6.2
redhat openssl 0.9.6b-3
hp hp-ux 11.23
checkpoint firewall-1 *
cisco ios 12.1(11)e
stonesoft stonegate 2.1
stonesoft stonegate 2.2.1
cisco application_and_content_networking_software *
cisco call_manager *
novell imanager 2.0
openssl openssl 0.9.7c
sun crypto_accelerator_4000 1.0
hp aaa_server *
cisco ciscoworks_common_management_foundation 2.1
tarantella tarantella_enterprise 3.40
redhat openssl 0.9.6-15
cisco threat_response *
avaya s8500 r2.0.0
openssl openssl 0.9.7
lite speed_technologies_litespeed_web_server 1.0.1
avaya s8700 r2.0.0
lite speed_technologies_litespeed_web_server 1.2_rc1
cisco firewall_services_module 1.1.3
sco openserver 5.0.6
bluecoat cacheos_ca_sa 4.1.10
4d webstar 5.2.4
cisco secure_content_accelerator 10000
avaya vsu 10000_r2.0.1
avaya intuity_audix s3400
4d webstar 5.2.2
cisco pix_firewall_software 6.3(3.109)
avaya converged_communications_server 2.0
redhat enterprise_linux 3.0
cisco content_services_switch_11500 *
avaya sg203 4.4
avaya sg200 4.4
cisco pix_firewall_software 6.1(1)
freebsd freebsd 5.2
cisco firewall_services_module 1.1.2
securecomputing sidewinder 5.2
avaya vsu 5000_r2.0.1
vmware gsx_server 2.5.1
4d webstar 5.3
avaya vsu 2000_r2.0.1
cisco pix_firewall_software 6.1(5)
stonesoft stonegate_vpn_client 2.0.7
stonesoft stonebeat_fullcluster 2.5
cisco pix_firewall_software 6.2(2)
avaya sg208 *
stonesoft stonebeat_securitycluster 2.5
avaya vsu 100_r2.0.1
symantec clientless_vpn_gateway_4400 5.0
sgi propack 2.3
openssl openssl 0.9.6e
novell edirectory 8.5.27
novell edirectory 8.5.12a
redhat enterprise_linux_desktop 3.0
checkpoint provider-1 4.1
openssl openssl 0.9.6j
stonesoft stonegate 2.2
avaya sg200 4.31.29
openssl openssl 0.9.6d
cisco webns 7.10_.0.06s
cisco pix_firewall_software 6.0
lite speed_technologies_litespeed_web_server 1.0.2
avaya sg203 4.31.29
novell edirectory 8.0
checkpoint vpn-1 vsx_ng_with_application_intelligence
cisco ios 12.1(11b)e
checkpoint firewall-1 next_generation_fp0
cisco pix_firewall_software 6.2(3.100)
cisco pix_firewall_software 6.3(1)
stonesoft servercluster 2.5
hp apache-based_web_server 2.0.43.04
cisco pix_firewall_software 6.1(4)
stonesoft stonegate_vpn_client 2.0.9
stonesoft stonebeat_fullcluster 3.0
cisco mds_9000 *
cisco ios 12.1(11b)e12
lite speed_technologies_litespeed_web_server 1.2_rc2
cisco webns 7.1_0.2.06
4d webstar 5.3.1
cisco pix_firewall_software 6.2(1)
stonesoft stonegate 1.5.18
neoteris instant_virtual_extranet 3.2
cisco pix_firewall_software 6.0(1)
checkpoint vpn-1 next_generation_fp1
stonesoft servercluster 2.5.2
openssl openssl 0.9.6h
avaya vsu 7500_r2.0.1
novell edirectory 8.7
cisco ios 12.1(11b)e14
avaya sg208 4.4
4d webstar 5.2.1
lite speed_technologies_litespeed_web_server 1.1.1
CVE-2004-0081 MEDIUM

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
avaya s8500 r2.0.1
bluecoat cacheos_ca_sa 4.1.12
openssl openssl 0.9.7b
checkpoint firewall-1 2.0
stonesoft stonegate 1.6.2
cisco pix_firewall_software 6.0(4.101)
cisco css11000_content_services_switch *
avaya vsu 500
openssl openssl 0.9.6i
stonesoft stonegate 2.0.4
bluecoat proxysg *
stonesoft stonebeat_webcluster 2.0
cisco css_secure_content_accelerator 1.0
cisco ciscoworks_common_services 2.2
redhat linux 7.3
neoteris instant_virtual_extranet 3.1
openbsd openbsd 3.4
openssl openssl 0.9.6g
stonesoft stonebeat_fullcluster 1_2.0
tarantella tarantella_enterprise 3.20
stonesoft stonegate 2.0.7
lite speed_technologies_litespeed_web_server 1.3
redhat linux 7.2
avaya vsu 5
4d webstar 5.2.3
cisco access_registrar *
hp hp-ux 11.00
avaya s8700 r2.0.1
avaya sg5 4.2
cisco pix_firewall_software 6.0(3)
cisco pix_firewall_software 6.0(4)
avaya s8300 r2.0.0
lite speed_technologies_litespeed_web_server 1.3_rc3
cisco pix_firewall_software 6.3
cisco pix_firewall 6.2.2_.111
avaya vsu 5x
cisco pix_firewall_software 6.3(3.102)
stonesoft stonebeat_fullcluster 2.0
stonesoft stonegate 2.0.9
avaya s8300 r2.0.1
cisco webns 6.10_b4
stonesoft stonegate 2.0.6
cisco ios 12.1(13)e9
stonesoft stonebeat_securitycluster 2.0
avaya sg5 4.4
cisco pix_firewall_software 6.3(2)
lite speed_technologies_litespeed_web_server 1.2.2
stonesoft stonegate 1.7.1
lite speed_technologies_litespeed_web_server 1.3_rc2
cisco pix_firewall_software 6.1(2)
freebsd freebsd 5.2.1
hp hp-ux 8.05
securecomputing sidewinder 5.2.0.02
securecomputing sidewinder 5.2.1.02
stonesoft stonebeat_webcluster 2.5
openssl openssl 0.9.6c
lite speed_technologies_litespeed_web_server 1.2.1
4d webstar 5.2
neoteris instant_virtual_extranet 3.3
freebsd freebsd 4.8
sgi propack 3.0
stonesoft stonegate_vpn_client 1.7
cisco ios 12.1(19)e1
cisco ios 12.2za
novell edirectory 8.6.2
novell edirectory 8.7.1
hp wbem a.02.00.00
openbsd openbsd 3.3
stonesoft stonebeat_fullcluster 1_3.0
cisco firewall_services_module 1.1_(3.005)
avaya sg5 4.3
stonesoft stonegate_vpn_client 1.7.2
redhat linux 8.0
checkpoint firewall-1 next_generation_fp1
stonesoft stonegate 1.7.2
securecomputing sidewinder 5.2.0.01
lite speed_technologies_litespeed_web_server 1.0.3
hp apache-based_web_server 2.0.43.00
checkpoint vpn-1 next_generation_fp0
stonesoft stonegate 2.0.1
avaya intuity_audix *
cisco pix_firewall_software 6.0(2)
openssl openssl 0.9.7a
stonesoft stonegate_vpn_client 2.0
stonesoft stonegate 1.7
freebsd freebsd 4.9
dell bsafe_ssl-j 3.0
apple mac_os_x 10.3.3
securecomputing sidewinder 5.2.0.04
avaya intuity_audix 5.1.46
cisco webns 6.10
hp hp-ux 11.11
cisco ios 12.2sy
cisco firewall_services_module 2.1_(0.208)
securecomputing sidewinder 5.2.1
cisco webns 7.2_0.0.03
securecomputing sidewinder 5.2.0.03
stonesoft stonegate 2.2.4
vmware gsx_server 2.5.1_build_5336
hp wbem a.01.05.08
cisco firewall_services_module *
neoteris instant_virtual_extranet 3.3.1
vmware gsx_server 3.0_build_7592
4d webstar 4.0
vmware gsx_server 2.0
sgi propack 2.4
cisco pix_firewall_software 6.2(3)
openssl openssl 0.9.6f
cisco pix_firewall_software 6.1(3)
stonesoft stonegate_vpn_client 2.0.8
stonesoft stonegate 2.0.8
tarantella tarantella_enterprise 3.30
checkpoint vpn-1 next_generation
dell bsafe_ssl-j 3.0.1
cisco okena_stormwatch 3.2
neoteris instant_virtual_extranet 3.0
openssl openssl 0.9.6k
hp wbem a.02.00.01
vmware gsx_server 2.0.1_build_2129
cisco ios 12.2(14)sy1
redhat openssl 0.9.7a-2
novell edirectory 8.5
cisco gss_4490_global_site_selector *
apple mac_os_x_server 10.3.3
lite speed_technologies_litespeed_web_server 1.3_rc1
lite speed_technologies_litespeed_web_server 1.3.1
cisco ios 12.2(14)sy
cisco webns 7.1_0.1.02
lite speed_technologies_litespeed_web_server 1.1
sco openserver 5.0.7
cisco pix_firewall_software 6.1
dell bsafe_ssl-j 3.1
stonesoft stonegate 1.6.3
stonesoft stonegate 2.0.5
checkpoint firewall-1 next_generation_fp2
stonesoft stonegate 1.5.17
cisco css_secure_content_accelerator 2.0
cisco gss_4480_global_site_selector *
cisco webns 7.10
freebsd freebsd 5.1
avaya intuity_audix s3210
novell imanager 1.5
cisco pix_firewall_software 6.2
redhat openssl 0.9.6b-3
hp hp-ux 11.23
checkpoint firewall-1 *
cisco ios 12.1(11)e
stonesoft stonegate 2.1
stonesoft stonegate 2.2.1
cisco application_and_content_networking_software *
cisco call_manager *
novell imanager 2.0
openssl openssl 0.9.7c
sun crypto_accelerator_4000 1.0
hp aaa_server *
cisco ciscoworks_common_management_foundation 2.1
tarantella tarantella_enterprise 3.40
cisco threat_response *
redhat openssl 0.9.6-15
avaya s8500 r2.0.0
openssl openssl 0.9.7
lite speed_technologies_litespeed_web_server 1.0.1
avaya s8700 r2.0.0
lite speed_technologies_litespeed_web_server 1.2_rc1
cisco firewall_services_module 1.1.3
sco openserver 5.0.6
bluecoat cacheos_ca_sa 4.1.10
4d webstar 5.2.4
cisco secure_content_accelerator 10000
avaya vsu 10000_r2.0.1
avaya intuity_audix s3400
4d webstar 5.2.2
cisco pix_firewall_software 6.3(3.109)
avaya converged_communications_server 2.0
cisco content_services_switch_11500 *
redhat enterprise_linux 3.0
avaya sg203 4.4
avaya sg200 4.4
cisco pix_firewall_software 6.1(1)
freebsd freebsd 5.2
cisco firewall_services_module 1.1.2
securecomputing sidewinder 5.2
avaya vsu 5000_r2.0.1
vmware gsx_server 2.5.1
4d webstar 5.3
avaya vsu 2000_r2.0.1
cisco pix_firewall_software 6.1(5)
stonesoft stonegate_vpn_client 2.0.7
stonesoft stonebeat_fullcluster 2.5
avaya sg208 *
cisco pix_firewall_software 6.2(2)
stonesoft stonebeat_securitycluster 2.5
symantec clientless_vpn_gateway_4400 5.0
avaya vsu 100_r2.0.1
sgi propack 2.3
openssl openssl 0.9.6e
novell edirectory 8.5.27
novell edirectory 8.5.12a
redhat enterprise_linux_desktop 3.0
checkpoint provider-1 4.1
openssl openssl 0.9.6j
stonesoft stonegate 2.2
avaya sg200 4.31.29
openssl openssl 0.9.6d
cisco webns 7.10_.0.06s
cisco pix_firewall_software 6.0
lite speed_technologies_litespeed_web_server 1.0.2
avaya sg203 4.31.29
novell edirectory 8.0
checkpoint vpn-1 vsx_ng_with_application_intelligence
cisco ios 12.1(11b)e
checkpoint firewall-1 next_generation_fp0
cisco pix_firewall_software 6.2(3.100)
cisco pix_firewall_software 6.3(1)
stonesoft servercluster 2.5
hp apache-based_web_server 2.0.43.04
cisco pix_firewall_software 6.1(4)
stonesoft stonebeat_fullcluster 3.0
stonesoft stonegate_vpn_client 2.0.9
cisco mds_9000 *
cisco ios 12.1(11b)e12
lite speed_technologies_litespeed_web_server 1.2_rc2
cisco webns 7.1_0.2.06
4d webstar 5.3.1
cisco pix_firewall_software 6.2(1)
stonesoft stonegate 1.5.18
neoteris instant_virtual_extranet 3.2
cisco pix_firewall_software 6.0(1)
checkpoint vpn-1 next_generation_fp1
stonesoft servercluster 2.5.2
openssl openssl 0.9.6h
avaya vsu 7500_r2.0.1
novell edirectory 8.7
cisco ios 12.1(11b)e14
avaya sg208 4.4
4d webstar 5.2.1
lite speed_technologies_litespeed_web_server 1.1.1
CVE-2004-0112 MEDIUM

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-125,

Products Affected

Vendor Product Version
avaya s8500 r2.0.1
bluecoat cacheos_ca_sa 4.1.12
openssl openssl 0.9.7b
checkpoint firewall-1 2.0
cisco pix_firewall_software 6.0(4.101)
cisco css11000_content_services_switch *
avaya vsu 500
openssl openssl 0.9.6i
bluecoat proxysg *
stonesoft stonebeat_webcluster 2.0
cisco ciscoworks_common_services 2.2
cisco css_secure_content_accelerator 1.0
redhat linux 7.3
neoteris instant_virtual_extranet 3.1
openbsd openbsd 3.4
openssl openssl 0.9.6g
stonesoft stonebeat_fullcluster 1_2.0
tarantella tarantella_enterprise 3.20
redhat linux 7.2
avaya vsu 5
4d webstar 5.2.3
cisco access_registrar *
hp hp-ux 11.00
avaya s8700 r2.0.1
checkpoint vpn-1 next_generation_fp2
avaya sg5 4.2
cisco pix_firewall_software 6.0(3)
cisco pix_firewall_software 6.0(4)
forcepoint stonegate 2.2.1
avaya s8300 r2.0.0
cisco pix_firewall_software 6.3
cisco pix_firewall 6.2.2_.111
avaya vsu 5x
cisco pix_firewall_software 6.3(3.102)
stonesoft stonebeat_fullcluster 2.0
avaya s8300 r2.0.1
cisco webns 6.10_b4
cisco ios 12.1(13)e9
forcepoint stonegate 1.5.18
stonesoft stonebeat_securitycluster 2.0
avaya sg5 4.4
cisco pix_firewall_software 6.3(2)
cisco pix_firewall_software 6.1(2)
freebsd freebsd 5.2.1
hp hp-ux 8.05
securecomputing sidewinder 5.2.0.02
securecomputing sidewinder 5.2.1.02
stonesoft stonebeat_webcluster 2.5
openssl openssl 0.9.6c
4d webstar 5.2
freebsd freebsd 4.8
neoteris instant_virtual_extranet 3.3
sgi propack 3.0
cisco ios 12.1(19)e1
cisco ios 12.2za
novell edirectory 8.6.2
novell edirectory 8.7.1
forcepoint stonegate 1.5.17
openbsd openbsd 3.3
hp wbem a.02.00.00
stonesoft stonebeat_fullcluster 1_3.0
cisco firewall_services_module 1.1_(3.005)
avaya sg5 4.3
redhat linux 8.0
forcepoint stonegate 2.0.5
checkpoint firewall-1 next_generation_fp1
securecomputing sidewinder 5.2.0.01
hp apache-based_web_server 2.0.43.00
forcepoint stonegate 2.0.6
checkpoint vpn-1 next_generation_fp0
avaya intuity_audix *
cisco pix_firewall_software 6.0(2)
openssl openssl 0.9.7a
freebsd freebsd 4.9
dell bsafe_ssl-j 3.0
apple mac_os_x 10.3.3
securecomputing sidewinder 5.2.0.04
avaya intuity_audix 5.1.46
cisco webns 6.10
hp hp-ux 11.11
cisco ios 12.2sy
forcepoint stonegate 2.2.4
cisco firewall_services_module 2.1_(0.208)
securecomputing sidewinder 5.2.1
cisco webns 7.2_0.0.03
securecomputing sidewinder 5.2.0.03
hp wbem a.01.05.08
vmware gsx_server 2.5.1_build_5336
cisco firewall_services_module *
neoteris instant_virtual_extranet 3.3.1
vmware gsx_server 3.0_build_7592
4d webstar 4.0
sgi propack 2.4
vmware gsx_server 2.0
cisco pix_firewall_software 6.2(3)
openssl openssl 0.9.6f
cisco pix_firewall_software 6.1(3)
dell bsafe_ssl-j 3.0.1
tarantella tarantella_enterprise 3.30
cisco okena_stormwatch 3.2
neoteris instant_virtual_extranet 3.0
openssl openssl 0.9.6k
vmware gsx_server 2.0.1_build_2129
cisco ios 12.2(14)sy1
hp wbem a.02.00.01
redhat openssl 0.9.7a-2
novell edirectory 8.5
cisco gss_4490_global_site_selector *
apple mac_os_x_server 10.3.3
forcepoint stonegate 2.0.9
cisco ios 12.2(14)sy
cisco webns 7.1_0.1.02
sco openserver 5.0.7
cisco pix_firewall_software 6.1
forcepoint stonegate 1.7.1
dell bsafe_ssl-j 3.1
checkpoint firewall-1 next_generation_fp2
cisco css_secure_content_accelerator 2.0
forcepoint stonegate 1.6.3
cisco gss_4480_global_site_selector *
freebsd freebsd 5.1
cisco webns 7.10
avaya intuity_audix s3210
redhat openssl 0.9.6b-3
cisco pix_firewall_software 6.2
novell imanager 1.5
hp hp-ux 11.23
checkpoint firewall-1 *
cisco ios 12.1(11)e
cisco application_and_content_networking_software *
cisco call_manager *
novell imanager 2.0
openssl openssl 0.9.7c
sun crypto_accelerator_4000 1.0
hp aaa_server *
cisco ciscoworks_common_management_foundation 2.1
tarantella tarantella_enterprise 3.40
forcepoint stonegate 2.0.1
redhat openssl 0.9.6-15
cisco threat_response *
avaya s8500 r2.0.0
openssl openssl 0.9.7
avaya s8700 r2.0.0
cisco firewall_services_module 1.1.3
forcepoint stonegate 2.1
sco openserver 5.0.6
forcepoint stonegate 2.2
bluecoat cacheos_ca_sa 4.1.10
4d webstar 5.2.4
cisco secure_content_accelerator 10000
avaya vsu 10000_r2.0.1
4d webstar 5.2.2
avaya intuity_audix s3400
avaya converged_communications_server 2.0
cisco pix_firewall_software 6.3(3.109)
cisco content_services_switch_11500 *
redhat enterprise_linux 3.0
avaya sg203 4.4
forcepoint stonegate 2.0.7
avaya sg200 4.4
cisco pix_firewall_software 6.1(1)
freebsd freebsd 5.2
cisco firewall_services_module 1.1.2
securecomputing sidewinder 5.2
avaya vsu 5000_r2.0.1
forcepoint stonegate 1.6.2
vmware gsx_server 2.5.1
4d webstar 5.3
forcepoint stonegate 1.7
avaya vsu 2000_r2.0.1
cisco pix_firewall_software 6.1(5)
stonesoft stonebeat_fullcluster 2.5
avaya sg208 *
stonesoft stonebeat_securitycluster 2.5
cisco pix_firewall_software 6.2(2)
avaya vsu 100_r2.0.1
symantec clientless_vpn_gateway_4400 5.0
sgi propack 2.3
openssl openssl 0.9.6e
novell edirectory 8.5.27
novell edirectory 8.5.12a
redhat enterprise_linux_desktop 3.0
forcepoint stonegate 2.0.4
checkpoint provider-1 4.1
openssl openssl 0.9.6j
avaya sg200 4.31.29
openssl openssl 0.9.6d
cisco webns 7.10_.0.06s
cisco pix_firewall_software 6.0
avaya sg203 4.31.29
novell edirectory 8.0
checkpoint vpn-1 vsx_ng_with_application_intelligence
cisco ios 12.1(11b)e
checkpoint firewall-1 next_generation_fp0
cisco pix_firewall_software 6.2(3.100)
forcepoint stonegate 1.7.2
cisco pix_firewall_software 6.3(1)
stonesoft servercluster 2.5
hp apache-based_web_server 2.0.43.04
cisco pix_firewall_software 6.1(4)
stonesoft stonebeat_fullcluster 3.0
cisco mds_9000 *
cisco ios 12.1(11b)e12
cisco webns 7.1_0.2.06
4d webstar 5.3.1
cisco pix_firewall_software 6.2(1)
neoteris instant_virtual_extranet 3.2
cisco pix_firewall_software 6.0(1)
checkpoint vpn-1 next_generation_fp1
stonesoft servercluster 2.5.2
openssl openssl 0.9.6h
avaya vsu 7500_r2.0.1
novell edirectory 8.7
cisco ios 12.1(11b)e14
litespeedtech litespeed_web_server 1.0.1
avaya sg208 4.4
forcepoint stonegate 2.0.8
4d webstar 5.2.1
CVE-2005-1708 MEDIUM

templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat reporter *
CVE-2005-1709 HIGH

Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat reporter *
CVE-2005-1710 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat reporter *
CVE-2005-3187 MEDIUM

The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP request that causes an out-of-bounds read.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat winproxy 6.0
CVE-2005-3654 HIGH

Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat webproxy 6.0
bluecoat webproxy 5.0
bluecoat webproxy 5.2
bluecoat webproxy 4.0
bluecoat webproxy 5.1
CVE-2005-4085 HIGH

Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat webproxy 6.0
bluecoat webproxy 5.0
bluecoat webproxy 5.2
bluecoat proxyav *
bluecoat webproxy 4.0
bluecoat webproxy 5.1
CVE-2006-0578 HIGH

Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat sgos 4.1.2.1
CVE-2007-0796 HIGH

Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat winproxy 6.0
bluecoat winproxy 6.1
CVE-2007-1685 HIGH

Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat k9_web_protection 3.2.36
CVE-2008-4485 MEDIUM

Cross-site scripting (XSS) vulnerability in the ICAP patience page in Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before 5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject arbitrary web script or HTML via the URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
bluecoat security_gateway_os 5.2
bluecoat security_gateway_os 5.3
bluecoat security_gateway_os 4.2
CVE-2009-1211 MEDIUM

Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
bluecoat proxysg_va-20 *
bluecoat proxysg_sg510-5 -
bluecoat proxysg_va-15 *
bluecoat proxysg_sg210-10 -
bluecoat proxysg_sg9000-20 -
bluecoat proxysg_sg210-5 -
bluecoat proxysg_sg510-10 -
bluecoat proxysg_va-5 *
bluecoat proxysg_sg810-20 -
bluecoat proxysg_sg210-25 -
bluecoat proxysg_sg9000-5 -
bluecoat proxysg_sg9000-10 -
bluecoat proxysg_sg510-25 -
bluecoat proxysg_sg510-20 -
bluecoat proxysg_sg810-25 -
bluecoat proxysg_sg810-10 -
bluecoat proxysg *
bluecoat proxysg_sg810-5 -
bluecoat proxysg_va-10 *
CVE-2010-5189 HIGH

Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated users to execute arbitrary CLI commands by leveraging read-only administrator privileges and establishing an HTTPS session.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
bluecoat sgos 4.2.2.2
bluecoat proxysg_sg510-5 -
bluecoat sgos 4.2.6
bluecoat sgos 4.2.3
bluecoat sgos 4.2.1.2
bluecoat proxysg_sg210-5 -
bluecoat sgos 4.2.3.4
bluecoat proxysg_sg810-20 -
bluecoat sgos 4.2.6.1
bluecoat proxysg_sg9000-10 -
bluecoat sgos 4.2.5
bluecoat proxysg_sg510-25 -
bluecoat sgos 3.2.6
bluecoat proxysg_sg810-25 -
bluecoat proxysg *
bluecoat sgos 5.5.4
bluecoat sgos *
bluecoat sgos 6.1
bluecoat sgos 4.2.3.7
bluecoat sgos 4.2.1.6
bluecoat sgos 4.2.3.26
bluecoat sgos 4.2.3.21
bluecoat proxysg_sg210-10 -
bluecoat proxysg_sg9000-20 -
bluecoat proxysg_sg510-10 -
bluecoat sgos 4.2.6.4
bluecoat proxysg_sg210-25 -
bluecoat sgos 4.2.3.12
bluecoat proxysg_sg9000-5 -
bluecoat sgos 4.2.4.1
bluecoat sgos 5.2.2.4
bluecoat sgos 4.2.2.1
bluecoat proxysg_sg510-20 -
bluecoat sgos 4.1.2.1
bluecoat proxysg_sg810-10 -
bluecoat sgos 4.2.7.1
bluecoat proxysg_sg810-5 -
bluecoat sgos 5.4.5
bluecoat sgos 4.2.2
bluecoat sgos 4.2.5.1
CVE-2010-5190 MEDIUM

The Active Content Transformation functionality in Blue Coat ProxySG before SGOS 4.3.4.2, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.2.1 allows remote attackers to bypass JavaScript detection via HTML entities.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
bluecoat sgos 4.2.2.2
bluecoat proxysg_sg510-5 -
bluecoat sgos 4.2.3
bluecoat sgos 4.2.6
bluecoat sgos 4.2.1.2
bluecoat sgos 4.2.3.4
bluecoat proxysg_sg210-5 -
bluecoat proxysg_sg810-20 -
bluecoat sgos 6.1.2
bluecoat sgos 4.2.6.1
bluecoat proxysg_sg9000-10 -
bluecoat sgos 4.2.5
bluecoat proxysg_sg510-25 -
bluecoat sgos 3.2.6
bluecoat proxysg_sg810-25 -
bluecoat proxysg *
bluecoat sgos 5.5.4
bluecoat sgos *
bluecoat sgos 4.2.3.7
bluecoat sgos 4.2.3.26
bluecoat sgos 4.2.1.6
bluecoat sgos 4.2.3.21
bluecoat proxysg_sg210-10 -
bluecoat proxysg_sg9000-20 -
bluecoat proxysg_sg510-10 -
bluecoat sgos 4.2.6.4
bluecoat proxysg_sg210-25 -
bluecoat sgos 4.2.3.12
bluecoat proxysg_sg9000-5 -
bluecoat sgos 5.2.2.4
bluecoat sgos 4.2.4.1
bluecoat sgos 4.2.2.1
bluecoat proxysg_sg510-20 -
bluecoat sgos 4.1.2.1
bluecoat proxysg_sg810-10 -
bluecoat sgos 4.2.7.1
bluecoat proxysg_sg810-5 -
bluecoat sgos 5.4.5
bluecoat sgos 4.2.5.1
bluecoat sgos 4.2.2
CVE-2010-5191 HIGH

Multiple cross-site request forgery (CSRF) vulnerabilities on the Blue Coat ProxyAV appliance before 3.2.6.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password, (2) modify a policy, or (3) restart the device.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-352,

Products Affected

Vendor Product Version
bluecoat proxyav *
bluecoat avos 3.1
bluecoat avos *
bluecoat avos 3.2
CVE-2010-5192 MEDIUM

Cross-site scripting (XSS) vulnerability in the Java Management Console in Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
bluecoat sgos 4.2.2.2
bluecoat proxysg_sg510-5 -
bluecoat sgos 4.2.6
bluecoat sgos 4.2.3
bluecoat sgos 4.2.1.2
bluecoat proxysg_sg210-5 -
bluecoat sgos 4.2.3.4
bluecoat proxysg_sg810-20 -
bluecoat sgos 6.1.2
bluecoat sgos 4.2.6.1
bluecoat proxysg_sg9000-10 -
bluecoat sgos 4.2.5
bluecoat sgos 3.2.6
bluecoat proxysg_sg510-25 -
bluecoat proxysg_sg810-25 -
bluecoat proxysg *
bluecoat sgos 5.5.4
bluecoat sgos *
bluecoat sgos 4.2.3.7
bluecoat sgos 4.2.1.6
bluecoat sgos 4.2.3.26
bluecoat sgos 4.2.3.21
bluecoat proxysg_sg210-10 -
bluecoat proxysg_sg9000-20 -
bluecoat proxysg_sg510-10 -
bluecoat sgos 4.2.6.4
bluecoat proxysg_sg210-25 -
bluecoat sgos 4.2.3.12
bluecoat proxysg_sg9000-5 -
bluecoat sgos 4.2.4.1
bluecoat sgos 5.2.2.4
bluecoat proxysg_sg510-20 -
bluecoat sgos 4.2.2.1
bluecoat sgos 4.1.2.1
bluecoat proxysg_sg810-10 -
bluecoat sgos 4.2.7.1
bluecoat proxysg_sg810-5 -
bluecoat sgos 5.4.5
bluecoat sgos 4.2.2
bluecoat sgos 4.2.5.1
CVE-2011-5124 HIGH

Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote attackers to execute arbitrary code via a large packet to the synchronization port (16102/tcp).

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
bluecoat proxysg 4.2.6
bluecoat proxysg 5.1.6.1
bluecoat proxysg 5.2.5.2
bluecoat proxysg 5.1
bluecoat proxysg 5.4.1.1
bluecoat proxysg 6
bluecoat proxyone *
bluecoat proxysg 5.3.2.1
bluecoat proxysg 5.2
bluecoat proxysg 5.3
bluecoat proxysg 5.2.2.4
bluecoat proxysg 4.3.2.3
bluecoat proxysg 5.4
CVE-2011-5125 MEDIUM

Cross-site scripting (XSS) vulnerability in Blue Coat Director before 5.5.2.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving the HTTP TRACE method.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
bluecoat director *
bluecoat director 5.5
bluecoat director 5.4
CVE-2011-5126 MEDIUM

Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers to obtain sensitive authentication information by leveraging read access to a downloaded core file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
bluecoat sgos 6.2.2
bluecoat sgos 6.1.2.1
bluecoat sgos 6.1.1.1
bluecoat sgos 6.1
bluecoat sgos 6.1.2
CVE-2011-5127 HIGH

Directory traversal vulnerability in Blue Coat Reporter 9.x before 9.2.4.13, 9.2.5.x before 9.2.5.1, and 9.3 before 9.3.1.2 on Windows allows remote attackers to read arbitrary files, and consequently execute arbitrary code, via an unspecified HTTP request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
bluecoat reporter 9.2.4.12
bluecoat reporter 9.2.5
bluecoat reporter 9.2.4.1
bluecoat reporter 9.3.1.1
CVE-2013-5959 HIGH

Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of service (memory consumption and dropped connections) via a recursive href in an HTML page, which triggers a large number of HTTP RW pipeline pre-fetch requests.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
bluecoat proxysgos 5.5
bluecoat proxysgos 6.2
bluecoat proxysg *
bluecoat proxysgos 6.1
bluecoat proxysgos 6.4
bluecoat proxysgos 5.3
bluecoat proxysgos 6.3
bluecoat proxysgos 5.4
bluecoat proxysgos 6.5
CVE-2014-2033 HIGH

The caching feature in SGOS in Blue Coat ProxySG 5.5 through 5.5.11.3, 6.1 through 6.1.6.3, 6.2 through 6.2.15.3, 6.4 through 6.4.6.1, and 6.3 and 6.5 before 6.5.4 allows remote authenticated users to bypass intended access restrictions during a time window after account deletion or modification by leveraging knowledge of previously valid credentials.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
bluecoat proxysgos 6.3
bluecoat proxysgos *
CVE-2014-2565 MEDIUM

The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-78,

Products Affected

Vendor Product Version
bluecoat content_analysis_system -
bluecoat content_analysis_system_software 1.1.1.1
bluecoat content_analysis_system_software 1.1
bluecoat content_analysis_system_software *
CVE-2015-1454 HIGH

Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-310,

Products Affected

Vendor Product Version
bluecoat proxyclient *
bluecoat unified_agent *
CVE-2015-8482 LOW

Blue Coat Unified Agent before 4.6.2 does not prevent modification of its configuration files when running in local enforcement mode, which allows local administrators to unblock categories or disable the agent via unspecified vectors.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
bluecoat unified_agent *
CVE-2015-8597 MEDIUM

Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
bluecoat proxysg *
bluecoat advanced_secure_gateway 6.6
CVE-2016-10259 MEDIUM

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
bluecoat ssl_visibility_appliance_sv800_firmware 3.11.2.1
bluecoat ssl_visibility_appliance_sv3800_firmware 3.9
bluecoat ssl_visibility_appliance_sv3800_firmware 3.11.1.1
bluecoat ssl_visibility_appliance_sv3800_firmware 3.10
bluecoat ssl_visibility_appliance_sv3800_firmware 3.11.1.2
bluecoat ssl_visibility_appliance_sv800_firmware 3.11.1.1
bluecoat ssl_visibility_appliance_sv2800_firmware 3.11.1.2
bluecoat ssl_visibility_appliance_sv1800_firmware 3.11
bluecoat ssl_visibility_appliance_sv1800_firmware 3.10
bluecoat ssl_visibility_appliance_sv2800_firmware 3.11
bluecoat ssl_visibility_appliance_sv2800_firmware 3.11.1.1
bluecoat ssl_visibility_appliance_sv1800_firmware 3.8.4
bluecoat ssl_visibility_appliance_sv800_firmware 3.9
bluecoat ssl_visibility_appliance_sv800_firmware 3.10
bluecoat ssl_visibility_appliance_sv3800_firmware 3.11.2.1
bluecoat ssl_visibility_appliance_sv800_firmware 3.11
bluecoat ssl_visibility_appliance_sv2800_firmware 3.8.4
bluecoat ssl_visibility_appliance_sv1800_firmware 3.9
bluecoat ssl_visibility_appliance_sv800_firmware 3.11.1.2
bluecoat ssl_visibility_appliance_sv3800_firmware 3.8.4
bluecoat ssl_visibility_appliance_sv1800_firmware 3.11.2.1
bluecoat ssl_visibility_appliance_sv1800_firmware 3.11.1.2
bluecoat ssl_visibility_appliance_sv800_firmware 3.8.4
bluecoat ssl_visibility_appliance_sv2800_firmware 3.11.2.1
bluecoat ssl_visibility_appliance_sv2800_firmware 3.10
bluecoat ssl_visibility_appliance_sv1800_firmware 3.11.1.1
bluecoat ssl_visibility_appliance_sv2800_firmware 3.9
bluecoat ssl_visibility_appliance_sv3800_firmware 3.11
CVE-2016-6594 MEDIUM

Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
bluecoat cacheflow 3.4
bluecoat advanced_secure_gateway 6.6
bluecoat proxysg 6.6
bluecoat proxysg 6.5
CVE-2016-9091 HIGH

Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
bluecoat advanced_secure_gateway *
bluecoat content_analysis_system_software *