VYPR

CVEs

101,977 total · page 1243 of 2,040

  • CVE-2021-3974HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Use After Free

  • CVE-2021-39236HigNov 19, 2021
    risk 0.50cvss 8.8epss 0.03

    In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

  • CVE-2021-39232HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.02

    In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

  • CVE-2021-37322HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.01

    GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.

  • CVE-2021-39928HigNov 18, 2021
    risk 0.49cvss 7.5epss 0.06

    NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39920HigNov 18, 2021
    risk 0.49cvss 7.5epss 0.03

    NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

  • CVE-2021-23193HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.01

    Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to…

  • CVE-2021-23167HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.00

    Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3); 8.40 versions prior to 8.40.2063…

  • CVE-2021-23162HigNov 18, 2021
    risk 0.50cvss 7.7epss 0.00

    Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior…

  • CVE-2021-23146HigNov 18, 2021
    risk 0.46cvss 7.1epss 0.01

    An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior…

  • CVE-2021-42524HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.

  • CVE-2021-42272HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious GIF file.

  • CVE-2021-42271HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.

  • CVE-2021-42270HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.

  • CVE-2021-42269HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.04

    Adobe Animate version 21.0.9 (and earlier) are affected by a use-after-free vulnerability in the processing of a malformed FLA file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2021-42267HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-42266HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-40760HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40759HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40758HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40757HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40755HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SGI file in the DoReadContinue function, potentially resulting in arbitrary code execution in the context of the current user. User…

  • CVE-2021-40754HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40753HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40752HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40751HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the…

  • CVE-2021-40733HigNov 18, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-35534HigNov 18, 2021
    risk 0.47cvss 7.2epss 0.02

    Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to…

  • CVE-2021-43669HigNov 18, 2021
    risk 0.00cvss 7.5epss 0.01

    A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted…

  • CVE-2021-43667HigNov 18, 2021
    risk 0.00cvss 7.5epss 0.01

    A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric.…

  • CVE-2021-35535HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.01

    Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during…

  • CVE-2021-36909HigNov 18, 2021
    risk 0.57cvss 8.8epss 0.02

    Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.

  • CVE-2021-36908HigNov 18, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.

  • CVE-2021-27024HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.01

    A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0

  • CVE-2021-43997HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected…

  • CVE-2021-41165HigNov 17, 2021
    risk 0.53cvss 8.2epss 0.01

    CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization,…

  • CVE-2021-33118HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the software installer for the Intel(R) Serial IO driver for Intel(R) NUC 11 Gen before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33071HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33063HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33062HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33058HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.4.0.21 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0180HigNov 17, 2021
    risk 0.48cvss 8.4epss 0.00

    Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access.

  • CVE-2021-0151HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0082HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0078HigNov 17, 2021
    risk 0.53cvss 8.1epss 0.00

    Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

  • CVE-2021-0071HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-0065HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0064HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0013HigNov 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2020-8741HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.