VYPR

CVEs

101,977 total · page 1488 of 2,040

  • CVE-2020-9098HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the insufficient validation of some parameter, successful exploit could cause device…

  • CVE-2020-5888HigApr 30, 2020
    risk 0.53cvss 8.1epss 0.01

    On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for adjacent network (layer 2) attackers to access local daemons and bypass port lockdown settings.

  • CVE-2020-1817HigApr 30, 2020
    risk 0.51cvss 7.8epss 0.00

    Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permission management of specific files, local attackers with low permissions can inject commands to exploit this vulnerability. Successful exploit may cause privilege…

  • CVE-2020-5891HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, undisclosed HTTP/2 requests can lead to a denial of service when sent to a virtual server configured with the Fallback Host setting and a server-side HTTP/2 profile.

  • CVE-2020-5883HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with HTTP explicit proxy and has an attached HTTP_PROXY_REQUEST iRule, POST requests sent to the virtual server cause an xdata memory leak.

  • CVE-2020-5882HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5, and 11.6.1-11.6.5.1, under certain conditions, the Intel QuickAssist Technology (QAT) cryptography driver may produce a Traffic Management Microkernel (TMM) core file.

  • CVE-2020-5881HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition (VE) is configured with VLAN groups and there are devices configured with OSPF connected to it, the Network Device Abstraction Layer (NDAL) Interfaces can lock up and in turn…

  • CVE-2020-5880HigApr 30, 2020
    risk 0.46cvss 7.1epss 0.01

    Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary files on the BIG-IP system, bypassing the authorization system. Resulting error messages may also reveal internal paths of the server.

  • CVE-2020-5879HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end servers unencrypted, even when a Server SSL profile is applied.

  • CVE-2020-5878HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.3, Traffic Management Microkernel (TMM) may restart on BIG-IP Virtual Edition (VE) while processing unusual IP traffic.

  • CVE-2020-5877HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, malformed input to the DATAGRAM::tcp iRules command within a FLOW_INIT event may lead to a denial of service.

  • CVE-2020-5876HigApr 30, 2020
    risk 0.53cvss 8.1epss 0.01

    On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exists where mcpd and other processes may make unencrypted connection attempts to a new configuration sync peer. The race condition can occur when changing the…

  • CVE-2020-5875HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may generate a core file and restart while processing SSL traffic with an HTTP/2 full proxy.

  • CVE-2020-5874HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM).

  • CVE-2020-5873HigApr 30, 2020
    risk 0.47cvss 7.2epss 0.01

    On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can…

  • CVE-2020-5872HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration enabled on platforms with Intel QAT hardware, the Traffic Management Microkernel (TMM) may stop responding and cause a failover…

  • CVE-2020-5871HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual servers. The problem can occur when ciphers, which have been blacklisted by the HTTP/2 RFC, are used on backend servers. This is a data-plane issue. There is…

  • CVE-2019-12425HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.05

    Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

  • CVE-2019-0235HigApr 30, 2020
    risk 0.63cvss 8.8epss 0.33

    Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

  • CVE-2020-11015HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create new UDID with same MAC address. Full…

  • CVE-2020-1752HigApr 30, 2020
    risk 0.46cvss 7.0epss 0.01

    A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by…

  • CVE-2020-12050HigApr 30, 2020
    risk 0.46cvss 7.0epss 0.00

    SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.

  • CVE-2020-6010HigApr 30, 2020
    risk 0.64cvss 8.8epss 0.49

    LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

  • CVE-2019-19220HigApr 30, 2020
    risk 0.57cvss 8.8epss 0.02

    BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).

  • CVE-2019-19219HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.

  • CVE-2019-19218HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.01

    BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.

  • CVE-2019-19217HigApr 30, 2020
    risk 0.57cvss 8.8epss 0.02

    BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.

  • CVE-2019-19216HigApr 30, 2020
    risk 0.57cvss 8.8epss 0.01

    BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.

  • CVE-2019-19215HigApr 30, 2020
    risk 0.57cvss 8.8epss 0.02

    A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote attackers to have unspecified impact via vectors related to the configured IP address or SMTP server.

  • CVE-2019-5621HigApr 29, 2020
    risk 0.54cvss 7.8epss 0.02

    ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

  • CVE-2019-5618HigApr 29, 2020
    risk 0.54cvss 7.8epss 0.02

    A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

  • CVE-2020-12479HigApr 29, 2020
    risk 0.00cvss 8.8epss 0.03

    TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.

  • CVE-2020-12478HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.09

    TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

  • CVE-2020-12477HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.02

    The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.

  • CVE-2020-11943HigApr 29, 2020
    risk 0.59cvss 8.8epss 0.24

    An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

  • CVE-2020-12470HigApr 29, 2020
    risk 0.47cvss 7.2epss 0.02

    MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.

  • CVE-2020-12468HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.01

    Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.

  • CVE-2019-16011HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2020-12473HigApr 29, 2020
    risk 0.47cvss 7.2epss 0.01

    MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.

  • CVE-2020-11020HigApr 29, 2020
    risk 0.48cvss 8.5epss 0.02

    Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extensions, by appending extra segments to the…

  • CVE-2020-12461HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.02

    PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over…

  • CVE-2020-8775HigApr 29, 2020
    risk 0.58cvss 8.9epss 0.01

    Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

  • CVE-2019-19165HigApr 29, 2020
    risk 0.47cvss 7.2epss 0.01

    AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u…

  • CVE-2020-8774HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.01

    Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.

  • CVE-2020-8773HigApr 29, 2020
    risk 0.58cvss 8.9epss 0.01

    The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-2575HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the…

  • CVE-2020-12446HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.01

    The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to…

  • CVE-2020-11677HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.01

    Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).

  • CVE-2020-11676HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.01

    Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).

  • CVE-2020-11675HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.01

    Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).