VYPR

CVEs

97,195 total · page 1365 of 1,944

  • CVE-2020-12422HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.02

    In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.

  • CVE-2020-12420HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.02

    When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

  • CVE-2020-12419HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.02

    When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10,…

  • CVE-2020-12417HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.03

    Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10,…

  • CVE-2020-12416HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.

  • CVE-2020-12411HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 77.

  • CVE-2020-12410HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.02

    Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects…

  • CVE-2020-12409HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77.

  • CVE-2020-12406HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox…

  • CVE-2020-12398HigJul 9, 2020
    risk 0.49cvss 7.5epss 0.01

    If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.

  • CVE-2020-7692HigJul 9, 2020
    risk 0.41cvss 7.4epss 0.02

    PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that…

  • CVE-2020-7457HigJul 9, 2020
    risk 0.58cvss 8.1epss 0.33

    In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious…

  • CVE-2020-5366HigJul 9, 2020
    risk 0.46cvss 7.1epss 0.02

    Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

  • CVE-2018-12371HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR <…

  • CVE-2020-9377HigKEVJul 9, 2020
    risk 0.71cvss 8.8epss 0.21

    D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-9376HigJul 9, 2020
    risk 0.50cvss 7.5epss 0.17

    D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-5604HigJul 9, 2020
    risk 0.53cvss 8.1epss 0.02

    Android App 'Mercari' (Japan version) prior to version 3.52.0 allows arbitrary method execution of a Java object by a remote attacker via a Man-In-The-Middle attack by using Java Reflection API of JavaScript code on WebView.

  • CVE-2020-5974HigJul 8, 2020
    risk 0.51cvss 7.8epss 0.00

    NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.

  • CVE-2020-15072HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.

  • CVE-2020-2034HigJul 8, 2020
    risk 0.53cvss 8.1epss 0.07

    An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be…

  • CVE-2020-2030HigJul 8, 2020
    risk 0.47cvss 7.2epss 0.03

    An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and all versions of PAN-OS 7.1 and PAN-OS…

  • CVE-2019-19417HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.01

    The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful…

  • CVE-2019-19416HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.01

    The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful…

  • CVE-2019-19415HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.01

    The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful…

  • CVE-2020-6938HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.01

    A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.

  • CVE-2020-5839HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

  • CVE-2020-11994HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.04

    Server-Side Template Injection and arbitrary file disclosure on Camel templating components

  • CVE-2020-5764HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.02

    MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by connecting to the MX Transfer session as a "sender" and sending a MessageType of…

  • CVE-2020-3973HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

  • CVE-2020-15008HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.01

    A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and…

  • CVE-2020-12736HigJul 7, 2020
    risk 0.47cvss 7.2epss 0.02

    Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the…

  • CVE-2020-15515HigJul 7, 2020
    risk 0.57cvss 8.8epss 0.02

    The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.

  • CVE-2020-15579HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via the KNOX API. The Samsung ID is SVE-2020-17318 (July 2020).

  • CVE-2020-15576HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.

  • CVE-2020-15574HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.

  • CVE-2020-10745HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest…

  • CVE-2020-15567HigJul 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of…

  • CVE-2020-15565HigJul 7, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require…

  • CVE-2020-5600HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a resource management error vulnerability, which may allow a remote attacker to stop the network…

  • CVE-2020-5598HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper access control vulnerability, which may which may allow a remote attacker tobypass access…

  • CVE-2020-5597HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network…

  • CVE-2020-5596HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to stop the network functions of the…

  • CVE-2020-15507HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors.

  • CVE-2020-4077HigJul 7, 2020
    risk 0.43cvss 7.7epss 0.01

    In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using both `contextIsolation` and…

  • CVE-2020-4076HigJul 7, 2020
    risk 0.44cvss 7.8epss 0.00

    In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using contextIsolation are affected. This is…

  • CVE-2020-9395HigJul 6, 2020
    risk 0.00cvss 8.0epss 0.01

    An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.

  • CVE-2020-9262HigJul 6, 2020
    risk 0.51cvss 7.8epss 0.01

    HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with high…

  • CVE-2020-9261HigJul 6, 2020
    risk 0.51cvss 7.8epss 0.01

    HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a type confusion vulnerability. The system does not properly check and transform the type of certain variable, the attacker tricks the user into installing then running a crafted application, successful…

  • CVE-2020-9100HigJul 6, 2020
    risk 0.51cvss 7.8epss 0.00

    Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing.

  • CVE-2020-6013HigJul 6, 2020
    risk 0.57cvss 8.8epss 0.02

    ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched…