VYPR

CVEs

101,977 total · page 1485 of 2,040

  • CVE-2020-11072HigMay 12, 2020
    risk 0.49cvss 8.6epss 0.01

    In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a…

  • CVE-2020-11071HigMay 12, 2020
    risk 0.49cvss 8.6epss 0.01

    SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction…

  • CVE-2020-10067HigMay 11, 2020
    risk 0.00cvss 7.5epss 0.00

    A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers. The impact would depend on the underlying system call and can range from denial of service to information leak to memory corruption resulting in code…

  • CVE-2020-10060HigMay 11, 2020
    risk 0.00cvss 8.0epss 0.02

    In updatehub_probe, right after JSON parsing is complete, objects\[1] is accessed from the output structure in two different places. If the JSON contained less than two elements, this access would reference unitialized stack memory. This could result in a crash, denial of…

  • CVE-2020-10058HigMay 11, 2020
    risk 0.00cvss 7.8epss 0.00

    Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated privileges. See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.

  • CVE-2020-10028HigMay 11, 2020
    risk 0.00cvss 7.8epss 0.00

    Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.

  • CVE-2020-10027HigMay 11, 2020
    risk 0.00cvss 7.8epss 0.01

    An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.

  • CVE-2020-10024HigMay 11, 2020
    risk 0.44cvss 7.8epss 0.01

    The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos…

  • CVE-2020-10021HigMay 11, 2020
    risk 0.00cvss 8.1epss 0.00

    Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.

  • CVE-2020-10019HigMay 11, 2020
    risk 0.46cvss 8.1epss 0.00

    USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. This could be used by a malicious USB host to exploit the buffer overflow. See NCC-ZEP-002 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later…

  • CVE-2020-9840HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.01

    In SwiftNIO Extras before 1.4.1, a logic issue was addressed with improved restrictions.

  • CVE-2020-5837HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    Symantec Endpoint Protection, prior to 14.3, may not respect file permissions when writing to log files that are replaced by symbolic links, which can lead to a potential elevation of privilege.

  • CVE-2020-5836HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection, prior to 14.3, can potentially reset the ACLs on a file as a limited user while Symantec Endpoint Protection's Tamper Protection feature is disabled.

  • CVE-2020-5835HigMay 11, 2020
    risk 0.46cvss 7.0epss 0.00

    Symantec Endpoint Protection Manager, prior to 14.3, has a race condition in client remote deployment which may result in an elevation of privilege on the remote machine.

  • CVE-2020-12790HigMay 11, 2020
    risk 0.42cvss 7.5epss 0.02

    In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.

  • CVE-2019-5500HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.02

    Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Denial of Service (DoS).

  • CVE-2019-19162HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.

  • CVE-2020-12785HigMay 11, 2020
    risk 0.53cvss 8.1epss 0.01

    cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).

  • CVE-2020-12760HigMay 11, 2020
    risk 0.50cvss 8.8epss 0.03

    An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code…

  • CVE-2020-12754HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application can obtain control of device input via the window system service. The LG ID is LVE-SMP-170011 (May 2020).

  • CVE-2020-12752HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020).

  • CVE-2020-12751HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung ID is SVE-2020-16943…

  • CVE-2020-12750HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via SPEN. The Samsung ID is SVE-2020-17019 (May 2020).

  • CVE-2020-12749HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI Wi-Fi drivers have a buffer overflow. The Samsung ID is SVE-2020-16906 (May 2020).

  • CVE-2020-12745HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipboard content via USSD. The Samsung ID is SVE-2019-16556 (May 2020).

  • CVE-2020-11866HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

  • CVE-2020-11865HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

  • CVE-2020-11108HigMay 11, 2020
    risk 0.66cvss 8.8epss 0.78

    The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to…

  • CVE-2020-12783HigMay 11, 2020
    risk 0.49cvss 7.5epss 0.05

    Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

  • CVE-2020-5538HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper Access Control in PALLET CONTROL Ver. 6.3 and earlier allows authenticated attackers to execute arbitrary code with the SYSTEM privilege on the computer where PALLET CONTROL is installed via unspecified vectors. PalletControl 7 to 9.1 are not affected by this…

  • CVE-2020-9315HigMay 10, 2020
    risk 0.55cvss 7.5epss 0.82

    ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the…

  • CVE-2020-12762HigMay 9, 2020
    risk 0.00cvss 7.8epss 0.02

    json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

  • CVE-2020-11531HigMay 8, 2020
    risk 0.58cvss 8.8epss 0.14

    The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP…

  • CVE-2018-20225HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that…

  • CVE-2019-14898HigMay 8, 2020
    risk 0.46cvss 7.0epss 0.00

    The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or…

  • CVE-2020-7291HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7290HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Active Response (MAR) for Linux prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7289HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Active Response (MAR) for Windows prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7288HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7287HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7286HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7285HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.5.0.94 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7267HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended…

  • CVE-2020-5741HigKEVMay 8, 2020
    risk 0.68cvss 7.2epss 0.73

    Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

  • CVE-2020-7266HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an…

  • CVE-2020-7265HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Mac prior to 10.6.9 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved…

  • CVE-2020-7264HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file.…

  • CVE-2020-12026HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

  • CVE-2020-12018HigMay 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.

  • CVE-2020-12014HigMay 8, 2020
    risk 0.49cvss 7.5epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.