VYPR

CVEs

101,988 total · page 1199 of 2,040

  • CVE-2021-39669HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2021-39668HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is needed…

  • CVE-2021-39663HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-39662HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not…

  • CVE-2021-39619HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2021-22824HigFeb 11, 2022
    risk 0.50cvss 7.5epss 0.14

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data…

  • CVE-2021-22806HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and…

  • CVE-2021-22804HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product:…

  • CVE-2021-22800HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M218 Logic Controller (V5.1.0.6 and prior)

  • CVE-2021-22798HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext� ComBox (All Versions)

  • CVE-2021-22796HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2021-22788HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet…

  • CVE-2021-22787HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340…

  • CVE-2021-22785HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to…

  • CVE-2021-22748HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2020-14523HigFeb 11, 2022
    risk 0.54cvss 8.3epss 0.02

    Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

  • CVE-2020-14521HigFeb 11, 2022
    risk 0.54cvss 8.3epss 0.01

    Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

  • CVE-2021-23597HigFeb 11, 2022
    risk 0.42cvss 7.5epss 0.02

    This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/SNYK-JS-FASTIFYMULTIPART-1290382).

  • CVE-2020-13677HigFeb 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.

  • CVE-2020-13670HigFeb 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10;…

  • CVE-2022-24289HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) feature is a web services-based technology that provides object persistence and query functionality to 'remote' applications. In Apache…

  • CVE-2021-35077HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible use after free scenario in compute offloads to DSP while multiple calls spawn a dynamic process in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35075HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible null pointer dereference due to lack of WDOG structure validation during registration in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35074HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35069HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-35068HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.01

    Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereference in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music,…

  • CVE-2021-30326HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/RRC Setup message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30323HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30322HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible out of bounds write due to improper validation of number of GPIOs configured in an internal parameters array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30318HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30309HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper size validation of QXDM commands can lead to memory corruption in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2022-0557HigFeb 11, 2022
    risk 0.00cvss 7.2epss 0.51

    OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2022-24958HigFeb 11, 2022
    risk 0.00cvss 7.8epss 0.00

    drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

  • CVE-2022-23773HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.03

    cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

  • CVE-2022-23772HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.03

    Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

  • CVE-2022-24647HigFeb 10, 2022
    risk 0.53cvss 8.1epss 0.01

    Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

  • CVE-2022-24646HigFeb 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

  • CVE-2022-0554HigFeb 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-24916HigFeb 10, 2022
    risk 0.00cvss 7.5epss 0.02

    Optimism before @eth-optimism/l2geth@0.5.11 allows economic griefing because a balance is duplicated upon contract self-destruction.

  • CVE-2022-23630HigFeb 10, 2022
    risk 0.00cvss 7.5epss 0.01

    Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This occurs when dependency…

  • CVE-2022-0017HigFeb 10, 2022
    risk 0.46cvss 7.0epss 0.00

    An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges under certain…

  • CVE-2022-0016HigFeb 10, 2022
    risk 0.48cvss 7.4epss 0.00

    An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect Before Logon under…

  • CVE-2021-44892HigFeb 10, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.

  • CVE-2022-24668HigFeb 9, 2022
    risk 0.42cvss 7.5epss 0.01

    A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error after frame parsing but…

  • CVE-2022-24667HigFeb 9, 2022
    risk 0.42cvss 7.5epss 0.01

    A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. There are a number of implementation errors in the…

  • CVE-2022-24666HigFeb 9, 2022
    risk 0.42cvss 7.5epss 0.01

    A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error when parsing a…

  • CVE-2022-24321HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server when receiving a malformed HTTP request. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All…

  • CVE-2022-24318HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.00

    A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions),…

  • CVE-2022-24317HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

  • CVE-2022-24316HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)