VYPR

CVEs

8,130 total · page 130 of 163

  • CVE-2017-7865CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.01

    FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.

  • CVE-2017-7864CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.

  • CVE-2017-7863CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.01

    FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.

  • CVE-2017-7862CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.

  • CVE-2017-7861CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.

  • CVE-2017-7860CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.

  • CVE-2017-7859CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.01

    FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.

  • CVE-2017-7858CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

  • CVE-2017-7857CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.03

    FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

  • CVE-2017-7856CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.02

    LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.

  • CVE-2016-10328CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.01

    FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

  • CVE-2016-10327CriApr 14, 2017
    risk 0.64cvss 9.8epss 0.01

    LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.

  • CVE-2016-6818CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS commands via a crafted SQL query. The vendor response is SAP Security Note 2361633.

  • CVE-2016-4899CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.04

    The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.

  • CVE-2016-4898CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.04

    The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.

  • CVE-2016-1155CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.05

    HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.

  • CVE-2015-2947CriApr 13, 2017
    risk 0.59cvss 9.1epss 0.01

    KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic.

  • CVE-2012-1301CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.03

    The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

  • CVE-2016-2566CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.01

    Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.

  • CVE-2016-10324CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.01

    In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.

  • CVE-2014-7921CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.00

    mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.

  • CVE-2014-7920CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.10

    mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.

  • CVE-2016-6143CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.06

    SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

  • CVE-2016-4800CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.01

    The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

  • CVE-2016-2555CriApr 13, 2017
    risk 0.73cvss 9.8epss 0.82

    SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.

  • CVE-2015-8282CriApr 13, 2017
    risk 0.69cvss 9.8epss 0.26

    SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.

  • CVE-2015-8271CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.01

    The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.

  • CVE-2015-6674CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.02

    Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplete fix of CVE-2012-1836.

  • CVE-2017-7628CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.00

    The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).

  • CVE-2017-7280CriApr 12, 2017
    risk 0.65cvss 9.8epss 0.10

    An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.

  • CVE-2017-7279CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.04

    An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.

  • CVE-2016-4337CriApr 12, 2017
    risk 0.67cvss 9.8epss 0.03

    SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.

  • CVE-2015-7564CriApr 12, 2017
    risk 0.67cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.

  • CVE-2016-6808CriApr 12, 2017
    risk 0.66cvss 9.8epss 0.29

    Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

  • CVE-2017-7722CriApr 12, 2017
    risk 0.72cvss 10.0epss 0.50

    In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.

  • CVE-2017-7719CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.01

    SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.

  • CVE-2017-3063CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.04

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3062CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.04

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3061CriApr 12, 2017
    risk 0.71cvss 9.8epss 0.54

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3060CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.10

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3059CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.04

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3037CriApr 12, 2017
    risk 0.64cvss 9.8epss 0.02

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-2989CriApr 12, 2017
    risk 0.59cvss 9.1epss 0.04

    Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database.

  • CVE-2017-7588CriApr 12, 2017
    risk 0.68cvss 9.8epss 0.17

    On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.

  • CVE-2016-7552CriApr 12, 2017
    risk 0.74cvss 9.8epss 0.93

    On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.

  • CVE-2016-7547CriApr 12, 2017
    risk 0.74cvss 9.8epss 0.89

    A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.

  • CVE-2017-7695CriApr 11, 2017
    risk 0.64cvss 9.8epss 0.00

    Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.

  • CVE-2017-7691CriApr 11, 2017
    risk 0.64cvss 9.8epss 0.01

    A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.

  • CVE-2017-7689CriApr 11, 2017
    risk 0.64cvss 9.8epss 0.03

    A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

  • CVE-2013-6647CriApr 11, 2017
    risk 0.64cvss 9.8epss 0.00

    A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.