VYPR

CVEs

102,253 total · page 1171 of 2,046

  • CVE-2021-44356HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-44355HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-44354HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-43257HigApr 14, 2022
    risk 0.44cvss 7.8epss 0.01

    Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.

  • CVE-2021-40426HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.02

    A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this…

  • CVE-2021-40402HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can…

  • CVE-2021-40400HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker…

  • CVE-2021-40398HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-40392HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

  • CVE-2021-21956HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.01

    A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21949HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    An improper array index validation vulnerability exists in the JPEG-JFIF Scan header parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to an out-of-bounds write and potential code exectuion. An attacker can provide a malicious file to trigger…

  • CVE-2021-21948HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the readDatHeadVec functionality of AnyCubic Chitubox AnyCubic Plugin 1.0.0. A specially-crafted GF file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21947HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these…

  • CVE-2021-21946HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these…

  • CVE-2021-21945HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer…

  • CVE-2021-21944HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer…

  • CVE-2021-21943HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21942HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.02

    An out-of-bounds write vulnerability exists in the TIFF YCbCr image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21939HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21914HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-25165HigApr 14, 2022
    risk 0.46cvss 7.0epss 0.01

    An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into the configuration file prior to the AWS VPN Client service…

  • CVE-2022-22198HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. On…

  • CVE-2022-22197HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker with an established BGP session to cause a Denial of Service (DoS). This…

  • CVE-2022-22195HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to trigger a counter overflow, eventually causing a Denial of Service (DoS). This issue affects Juniper Networks Junos OS…

  • CVE-2022-22194HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juniper Networks Junos OS Evolved on PTX10003, PTX10004, and PTX10008 allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Continued receipt of these…

  • CVE-2022-22190HigApr 14, 2022
    risk 0.48cvss 7.4epss 0.01

    An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature was introduced in…

  • CVE-2022-22189HigApr 14, 2022
    risk 0.47cvss 7.3epss 0.00

    An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently authenticated to.…

  • CVE-2022-22188HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS). The…

  • CVE-2022-22187HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.00

    An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper Identity Management Service (JIMS) allows an unprivileged user to trigger a repair operation. Running a repair operation, in turn, will trigger a number of file…

  • CVE-2022-22186HigApr 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress interface, instead of being discarded. Such traffic being…

  • CVE-2022-22185HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated attacker to cause a Denial of Service (DoS) by sending a specific fragmented packet to the device, resulting in a flowd process crash, which is responsible for packet forwarding.…

  • CVE-2022-22183HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to consume all…

  • CVE-2022-22182HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects: Juniper…

  • CVE-2022-22181HigApr 14, 2022
    risk 0.52cvss 8.0epss 0.01

    A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web. This may allow the attacker…

  • CVE-2022-27008HigApr 14, 2022
    risk 0.00cvss 7.5epss 0.02

    nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array.

  • CVE-2022-1258HigApr 14, 2022
    risk 0.55cvss 8.4epss 0.01

    A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.

  • CVE-2022-1256HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges…

  • CVE-2022-27457HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

  • CVE-2022-27456HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

  • CVE-2022-27455HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

  • CVE-2022-27452HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.

  • CVE-2022-27451HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

  • CVE-2022-27449HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.

  • CVE-2022-27448HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

  • CVE-2022-27447HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.

  • CVE-2022-27446HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.

  • CVE-2022-27445HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

  • CVE-2022-27444HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.

  • CVE-2021-43289HigApr 14, 2022
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

  • CVE-2021-43286HigApr 14, 2022
    risk 0.00cvss 8.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.