VYPR

CVEs

112,174 total · page 1098 of 2,244

  • CVE-2020-24088HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.

  • CVE-2022-34227HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-34224HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-28836HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-28835HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2022-28834HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InCopy versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-28833HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-28832HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to…

  • CVE-2022-28831HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InDesign versions 17.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2019-16471HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2019-16470HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…

  • CVE-2023-36161HigSep 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via Wi-Fi deauthentication.

  • CVE-2023-3612HigSep 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

  • CVE-2023-4585HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2023-4584HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…

  • CVE-2023-4583HigSep 11, 2023
    risk 0.49cvss 7.5epss 0.01

    When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability…

  • CVE-2023-4582HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability…

  • CVE-2023-4576HigSep 11, 2023
    risk 0.56cvss 8.6epss 0.01

    On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*…

  • CVE-2023-4877HigSep 10, 2023
    risk 0.00cvss 7.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.

  • CVE-2023-4876HigSep 10, 2023
    risk 0.00cvss 7.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.

  • CVE-2023-41915HigSep 9, 2023
    risk 0.53cvss 8.1epss 0.01

    OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.

  • CVE-2023-42278HigSep 8, 2023
    risk 0.42cvss 7.5epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().

  • CVE-2023-30995HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268.

  • CVE-2022-33164HigSep 8, 2023
    risk 0.57cvss 8.7epss 0.01

    IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view or write to arbitrary files on the system. IBM X-Force ID: 228579.

  • CVE-2023-41578HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.

  • CVE-2023-38736HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.6, when installed to run as ADMIN or SYSTEM, is vulnerable to a local escalation of privilege attack that a normal user could utilize to gain SYSTEM permissions. IBM X-Force ID: 262542.

  • CVE-2023-39322HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

  • CVE-2023-39321HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

  • CVE-2023-40924HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.03

    SolarView Compact < 6.00 is vulnerable to Directory Traversal.

  • CVE-2023-39584HigSep 8, 2023
    risk 0.44cvss 7.5epss 0.32

    Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

  • CVE-2023-4807HigSep 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an…

  • CVE-2023-41594HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.

  • CVE-2023-40953HigSep 8, 2023
    risk 0.57cvss 8.8epss 0.00

    icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2023-39620HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest account function.

  • CVE-2014-5329HigSep 8, 2023
    risk 0.52cvss 7.5epss 0.02

    GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administrative operation. 8001/tcp is served by a version of Apache HTTP server containing a flaw in handling HTTP requests…

  • CVE-2023-40271HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part…

  • CVE-2023-36184HigSep 8, 2023
    risk 0.00cvss 7.5epss 0.01

    CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.

  • CVE-2021-33834HigSep 8, 2023
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory corruption or a system crash.

  • CVE-2023-4685HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

  • CVE-2023-4528HigSep 7, 2023
    risk 0.49cvss 7.2epss 0.27

    Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface

  • CVE-2023-41064HigKEVSep 7, 2023
    risk 0.64cvss 7.8epss 0.15

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to…

  • CVE-2023-41061HigKEVSep 7, 2023
    risk 0.63cvss 7.8epss 0.03

    A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

  • CVE-2023-40060HigSep 7, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  SolarWinds found that the…

  • CVE-2023-30800HigSep 7, 2023
    risk 0.49cvss 7.5epss 0.02

    The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted.…

  • CVE-2022-30646HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-30645HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-30644HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30643HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-30642HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-30641HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…