VYPR

CVEs

8,985 total · page 115 of 180

  • CVE-2019-1010298CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.05

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

  • CVE-2019-1010297CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.01

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component is: optee_os. The fixed version is: 3.4.0 and later.

  • CVE-2019-1010296CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.01

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

  • CVE-2019-1010295CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.00

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.

  • CVE-2019-1010293CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.00

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

  • CVE-2017-14854CriJun 3, 2019
    risk 0.60cvss 9.1epss 0.11

    A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.

  • CVE-2017-14851CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.

  • CVE-2017-14728CriJun 3, 2019
    risk 0.65cvss 9.8epss 0.10

    An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication…

  • CVE-2018-16988CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the…

  • CVE-2019-11068CriApr 10, 2019
    risk 0.57cvss 9.8epss 0.01

    libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

  • CVE-2019-9201CriFeb 26, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

  • CVE-2018-7791CriAug 29, 2018
    risk 0.64cvss 9.8epss 0.00

    A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an…

  • CVE-2018-7790CriAug 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability…

  • CVE-2018-8859CriJul 24, 2018
    risk 0.64cvss 9.8epss 0.00

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the…

  • CVE-2018-8855CriJul 24, 2018
    risk 0.64cvss 9.8epss 0.00

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.

  • CVE-2018-8851CriJul 24, 2018
    risk 0.64cvss 9.8epss 0.00

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer…

  • CVE-2018-10627CriJul 24, 2018
    risk 0.64cvss 9.8epss 0.00

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and…

  • CVE-2018-1000301CriMay 24, 2018
    risk 0.52cvss 9.1epss 0.03

    curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability…

  • CVE-2018-11091CriMay 14, 2018
    risk 0.64cvss 9.9epss 0.02

    An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system commands. This vulnerability occurs because an attacker is able to adjust the…

  • CVE-2017-18001CriDec 31, 2017
    risk 0.69cvss 9.8epss 0.23

    Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

  • CVE-2017-17992CriDec 30, 2017
    risk 0.64cvss 9.8epss 0.01

    Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name parameter in a download_form action.

  • CVE-2014-9515CriDec 29, 2017
    risk 0.57cvss 9.8epss 0.05

    Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

  • CVE-2014-3630CriDec 29, 2017
    risk 0.64cvss 9.8epss 0.01

    XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.

  • CVE-2014-0121CriDec 29, 2017
    risk 0.57cvss 9.8epss 0.02

    The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

  • CVE-2017-17974CriDec 29, 2017
    risk 0.64cvss 9.8epss 0.00

    BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allows remote attackers to obtain sensitive information via a request for isc/get_sid_js.aspx or isc/get_sid.aspx, as demonstrated by obtaining administrative…

  • CVE-2017-17968CriDec 29, 2017
    risk 0.71cvss 9.8epss 0.55

    A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.

  • CVE-2014-4914CriDec 29, 2017
    risk 0.64cvss 9.8epss 0.03

    The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

  • CVE-2017-17959CriDec 28, 2017
    risk 0.64cvss 9.8epss 0.00

    PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.

  • CVE-2017-17957CriDec 28, 2017
    risk 0.64cvss 9.8epss 0.00

    PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.

  • CVE-2017-17951CriDec 28, 2017
    risk 0.64cvss 9.8epss 0.00

    PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.

  • CVE-2017-5641CriDec 28, 2017
    risk 0.61cvss 9.8epss 0.48

    Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types…

  • CVE-2017-17932CriDec 28, 2017
    risk 0.73cvss 9.8epss 0.77

    A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.

  • CVE-2014-8389CriDec 28, 2017
    risk 0.65cvss 9.8epss 0.14

    cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware…

  • CVE-2015-7669CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.01

    Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file…

  • CVE-2015-6237CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.01

    The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."

  • CVE-2017-9944CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.

  • CVE-2017-17931CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.00

    PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.

  • CVE-2017-17928CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.00

    PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.

  • CVE-2017-17906CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.00

    PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.

  • CVE-2017-17900CriDec 27, 2017
    risk 0.57cvss 9.8epss 0.00

    SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.

  • CVE-2017-17899CriDec 27, 2017
    risk 0.57cvss 9.8epss 0.00

    SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.

  • CVE-2017-17897CriDec 27, 2017
    risk 0.57cvss 9.8epss 0.00

    SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2017-17895CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.00

    Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.

  • CVE-2017-17892CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.00

    Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter.

  • CVE-2017-17878CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" setting).

  • CVE-2017-17877CriDec 27, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers…

  • CVE-2017-17875CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

  • CVE-2017-17873CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

  • CVE-2017-17872CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

  • CVE-2017-17871CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.