VYPR

CVEs

101,988 total · page 1227 of 2,040

  • CVE-2021-45488HigDec 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.

  • CVE-2021-45487HigDec 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.

  • CVE-2021-45485HigDec 25, 2021
    risk 0.00cvss 7.5epss 0.04

    In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.

  • CVE-2021-45484HigDec 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.

  • CVE-2021-23574HigDec 24, 2021
    risk 0.49cvss 7.5epss 0.02

    All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).

  • CVE-2021-23490HigDec 24, 2021
    risk 0.42cvss 7.5epss 0.02

    The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.

  • CVE-2021-23772HigDec 24, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target…

  • CVE-2021-20874HigDec 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the…

  • CVE-2021-20827HigDec 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and…

  • CVE-2021-20826HigDec 24, 2021
    risk 0.49cvss 7.6epss 0.00

    Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1…

  • CVE-2021-45470HigDec 23, 2021
    risk 0.00cvss 7.5epss 0.02

    lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.

  • CVE-2021-3621HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.03

    A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root…

  • CVE-2021-44542HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A memory leak vulnerability was found in Privoxy when handling errors.

  • CVE-2021-44541HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.

  • CVE-2021-44540HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.

  • CVE-2021-43989HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.

  • CVE-2021-3584HigDec 23, 2021
    risk 0.00cvss 7.2epss 0.04

    A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity…

  • CVE-2021-20318HigDec 23, 2021
    risk 0.47cvss 7.2epss 0.02

    The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.

  • CVE-2020-3886HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2018-4302HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or…

  • CVE-2017-2488HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords.

  • CVE-2017-13908HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A local attacker may be able to execute…

  • CVE-2017-13906HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A malicious application may be able to elevate privileges.

  • CVE-2017-13905HigDec 23, 2021
    risk 0.53cvss 8.1epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.

  • CVE-2017-13892HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may…

  • CVE-2017-13880HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.

  • CVE-2017-13835HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. An application may be able to execute arbitrary code with elevated privileges.

  • CVE-2021-45469HigDec 23, 2021
    risk 0.00cvss 7.8epss 0.01

    In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.

  • CVE-2021-40161HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.

  • CVE-2021-40160HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.02

    PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-4118HigDec 23, 2021
    risk 0.44cvss 7.8epss 0.01

    pytorch-lightning is vulnerable to Deserialization of Untrusted Data

  • CVE-2021-43854HigDec 23, 2021
    risk 0.42cvss 7.5epss 0.03

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReDoS) attacks. The…

  • CVE-2021-23175HigDec 23, 2021
    risk 0.53cvss 8.2epss 0.00

    NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data…

  • CVE-2021-44600HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was…

  • CVE-2021-44599HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. A crafted payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The…

  • CVE-2021-44273HigDec 23, 2021
    risk 0.00cvss 7.4epss 0.01

    e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates…

  • CVE-2021-4144HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.02

    TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.

  • CVE-2021-45463HigDec 23, 2021
    risk 0.00cvss 7.8epss 0.01

    load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before…

  • CVE-2021-45462HigDec 23, 2021
    risk 0.00cvss 7.5epss 0.04

    In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.

  • CVE-2021-20050HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.

  • CVE-2021-20049HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.

  • CVE-2021-4079HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.

  • CVE-2021-4078HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4067HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4066HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4065HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4064HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4063HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4062HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4061HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.