VYPR

CVEs

8,145 total · page 125 of 163

  • CVE-2017-4992CriJun 13, 2017
    risk 0.57cvss 9.8epss 0.00

    An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior to v24.10, 30.x versions prior to 30.3, and other versions prior to v37. There is privilege escalation (arbitrary password reset) with user invitations.

  • CVE-2017-4955CriJun 13, 2017
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications errand in the PCF Elastic Runtime tile.

  • CVE-2017-2773CriJun 13, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime, aka an "Unauthenticated JWT signing algorithm in multiple components" issue.

  • CVE-2016-8218CriJun 13, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

  • CVE-2016-6655CriJun 13, 2017
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a common script used by many Cloud Foundry components. A malicious user may exploit numerous vectors to execute arbitrary commands on servers running Cloud Foundry.

  • CVE-2014-9984CriJun 12, 2017
    risk 0.64cvss 9.8epss 0.01

    nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

  • CVE-2017-9544CriJun 12, 2017
    risk 0.73cvss 9.8epss 0.80

    There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.

  • CVE-2017-9542CriJun 11, 2017
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.

  • CVE-2016-7836CriKEVJun 9, 2017
    risk 0.79cvss 9.8epss 0.36

    SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

  • CVE-2016-7835CriJun 9, 2017
    risk 0.59cvss 9.1epss 0.03

    Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.

  • CVE-2016-7806CriJun 9, 2017
    risk 0.65cvss 9.8epss 0.11

    I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2016-6093CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.00

    IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2015-2692CriJun 8, 2017
    risk 0.65cvss 10.0epss 0.01

    AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.

  • CVE-2016-4473CriJun 8, 2017
    risk 0.65cvss 9.8epss 0.17

    /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.

  • CVE-2017-4918CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.03

    VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed.

  • CVE-2016-7050CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.01

    SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

  • CVE-2016-5405CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.01

    389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

  • CVE-2016-3690CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.02

    The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

  • CVE-2016-2034CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.

  • CVE-2017-5878CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.03

    The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data.

  • CVE-2014-8687CriJun 8, 2017
    risk 0.71cvss 9.8epss 0.50

    Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

  • CVE-2017-6640CriJun 8, 2017
    risk 0.68cvss 9.8epss 0.53

    A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to the affected software by using the credentials for this default user account. A successful exploit could allow the attacker to use this default user account to log in to the affected software and gain access to the administrative console of a DCNM server. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software releases prior to Release 10.2(1) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd95346.

  • CVE-2017-6639CriJun 8, 2017
    risk 0.67cvss 9.8epss 0.41

    A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The vulnerability is due to the lack of authentication and authorization mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could exploit this vulnerability by remotely connecting to the debugging tool via TCP. A successful exploit could allow the attacker to access sensitive information about the affected software or execute arbitrary code with root privileges on the affected system. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software Releases 10.1(1) and 10.1(2) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd09961.

  • CVE-2017-4907CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.03

    VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

  • CVE-2017-4901CriJun 8, 2017
    risk 0.68cvss 9.9epss 0.14

    The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.

  • CVE-2015-7346CriJun 7, 2017
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in ZCMS 1.1.

  • CVE-2017-4917CriJun 7, 2017
    risk 0.64cvss 9.8epss 0.00

    VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.

  • CVE-2017-4914CriJun 7, 2017
    risk 0.68cvss 9.8epss 0.13

    VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

  • CVE-2017-1196CriJun 7, 2017
    risk 0.64cvss 9.8epss 0.00

    IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.

  • CVE-2016-6087CriJun 7, 2017
    risk 0.64cvss 9.8epss 0.01

    IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918.

  • CVE-2015-7326CriJun 7, 2017
    risk 0.64cvss 9.8epss 0.02

    XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.

  • CVE-2017-7312CriJun 7, 2017
    risk 0.67cvss 9.8epss 0.08

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).

  • CVE-2016-9961CriJun 6, 2017
    risk 0.64cvss 9.8epss 0.03

    game-music-emu before 0.6.1 mishandles unspecified integer values.

  • CVE-2016-0726CriJun 6, 2017
    risk 0.64cvss 9.8epss 0.00

    The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

  • CVE-2017-9436CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.00

    TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.

  • CVE-2017-9435CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.00

    Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).

  • CVE-2017-8837CriJun 5, 2017
    risk 0.68cvss 9.8epss 0.11

    Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.

  • CVE-2017-8835CriJun 5, 2017
    risk 0.72cvss 9.8epss 0.64

    SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.

  • CVE-2017-9430CriJun 5, 2017
    risk 0.68cvss 9.8epss 0.15

    Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.

  • CVE-2017-9433CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.01

    Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1Parser.cxx.

  • CVE-2017-9432CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.01

    Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in lib/StarWriterStruct.cxx.

  • CVE-2017-9431CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.01

    Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.

  • CVE-2017-9417CriJun 4, 2017
    risk 0.69cvss 9.8epss 0.31

    Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

  • CVE-2017-9364CriJun 2, 2017
    risk 0.64cvss 9.8epss 0.00

    Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.

  • CVE-2017-9363CriJun 2, 2017
    risk 0.64cvss 9.8epss 0.04

    Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.

  • CVE-2017-9360CriJun 2, 2017
    risk 0.64cvss 9.8epss 0.00

    WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.

  • CVE-2015-5473CriJun 1, 2017
    risk 0.67cvss 9.8epss 0.47

    Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addDriver or to execute arbitrary code with SYSTEM privileges via unspecified parameters to (3) uploadCloning.html, (4) fileupload.html, (5) uploadFirmware.html, or (6) upload/driver.

  • CVE-2015-0936CriJun 1, 2017
    risk 0.74cvss 9.8epss 0.86

    Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

  • CVE-2017-7494CriKEVMay 30, 2017
    risk 0.85cvss 9.8epss 0.94

    Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

  • CVE-2017-9294CriMay 29, 2017
    risk 0.64cvss 9.8epss 0.04

    RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports.