VYPR

CVEs

8,909 total · page 121 of 179

  • CVE-2017-2894CriNov 7, 2017
    risk 0.64cvss 9.8epss 0.05

    An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially…

  • CVE-2017-2892CriNov 7, 2017
    risk 0.64cvss 9.8epss 0.02

    An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in information disclosure, denial of…

  • CVE-2017-2891CriNov 7, 2017
    risk 0.64cvss 9.8epss 0.03

    An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send…

  • CVE-2017-2864CriNov 7, 2017
    risk 0.64cvss 9.8epss 0.01

    An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker resulting in authentication bypass. An attacker can send a…

  • CVE-2017-12085CriNov 7, 2017
    risk 0.59cvss 9.0epss 0.01

    An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Circle device. An attacker needs network connectivity to the Internet to trigger this vulnerability.

  • CVE-2017-15887CriNov 7, 2017
    risk 0.64cvss 9.8epss 0.00

    An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.

  • CVE-2017-16638CriNov 6, 2017
    risk 0.64cvss 9.8epss 0.00

    The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script.

  • CVE-2017-16548CriNov 6, 2017
    risk 0.64cvss 9.8epss 0.03

    The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified…

  • CVE-2017-16543CriNov 5, 2017
    risk 0.67cvss 9.8epss 0.02

    Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

  • CVE-2017-1000171CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.00

    Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.

  • CVE-2017-1000154CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.01

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.

  • CVE-2017-1000153CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.00

    Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can…

  • CVE-2017-1000152CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.00

    Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out…

  • CVE-2017-16523CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.03

    MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented.

  • CVE-2017-11767CriNov 2, 2017
    risk 0.58cvss 9.8epss 0.17

    ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".

  • CVE-2017-16510CriNov 2, 2017
    risk 0.57cvss 9.8epss 0.04

    WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

  • CVE-2017-1000121CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.01

    The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect…

  • CVE-2017-1000245CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.00

    The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.

  • CVE-2017-14027CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.00

    A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC…

  • CVE-2017-14021CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.00

    A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d,…

  • CVE-2017-15535CriNov 1, 2017
    risk 0.59cvss 9.1epss 0.00

    MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify…

  • CVE-2017-14375CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.02

    EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including…

  • CVE-2017-1000257CriOct 31, 2017
    risk 0.59cvss 9.1epss 0.01

    An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data…

  • CVE-2017-14356CriOct 31, 2017
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.

  • CVE-2017-15993CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.

  • CVE-2017-15992CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.

  • CVE-2017-15991CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951,…

  • CVE-2017-15990CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.09

    Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.

  • CVE-2017-15989CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.

  • CVE-2017-15988CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.

  • CVE-2017-15987CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.

  • CVE-2017-15986CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    CPA Lead Reward Script allows SQL Injection via the username parameter.

  • CVE-2017-15985CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.

  • CVE-2017-15984CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.

  • CVE-2017-15983CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

  • CVE-2017-15982CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

  • CVE-2017-15981CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

  • CVE-2017-15980CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.

  • CVE-2017-15979CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.

  • CVE-2017-15978CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

  • CVE-2017-15977CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.01

    Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.

  • CVE-2015-9245CriOct 31, 2017
    risk 0.64cvss 9.8epss 0.00

    Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.

  • CVE-2017-10151CriOct 30, 2017
    risk 0.66cvss 10.0epss 0.14

    Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2014-0073CriOct 30, 2017
    risk 0.58cvss 9.8epss 0.11

    The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote…

  • CVE-2013-4366CriOct 30, 2017
    risk 0.57cvss 9.8epss 0.01

    http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.

  • CVE-2012-4449CriOct 30, 2017
    risk 0.64cvss 9.8epss 0.00

    Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.

  • CVE-2017-15597CriOct 30, 2017
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a…

  • CVE-2015-3249CriOct 30, 2017
    risk 0.64cvss 9.8epss 0.04

    The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2)…

  • CVE-2014-3624CriOct 30, 2017
    risk 0.64cvss 9.8epss 0.00

    Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.

  • CVE-2012-5358CriOct 30, 2017
    risk 0.64cvss 9.8epss 0.01

    The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrary files and consequently bypass authentication, modify viewstate, cause a denial…