VYPR

CVEs

101,977 total · page 1494 of 2,040

  • CVE-2020-8099HigApr 21, 2020
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects: Bitdefender Antivirus Free versions prior to 1.0.17.

  • CVE-2020-11968HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.03

    In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a…

  • CVE-2020-11964HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.02

    In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial…

  • CVE-2020-11958HigApr 21, 2020
    risk 0.00cvss 7.8epss 0.02

    re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.

  • CVE-2020-9276HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stack-based buffer overflow. Unauthenticated exploitation is possible by combining…

  • CVE-2020-11946HigApr 20, 2020
    risk 0.53cvss 7.5epss 0.52

    Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

  • CVE-2020-3946HigApr 20, 2020
    risk 0.49cvss 7.5epss 0.01

    InstallBuilder AutoUpdate tool and regular installers enabling built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).

  • CVE-2020-11753HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default…

  • CVE-2017-18837HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18830HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18829HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18826HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18822HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18849HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R6900P before…

  • CVE-2017-18848HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.0.36, AC1450 before 1.0.0.36, R7300 before 1.0.0.54, and R8500 before 1.0.2.94.

  • CVE-2017-18845HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38.

  • CVE-2017-18844HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.

  • CVE-2017-18843HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.

  • CVE-2017-18842HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200DW-1FRNAS before 1.0.0.32.

  • CVE-2017-18838HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before…

  • CVE-2017-18850HigApr 20, 2020
    risk 0.55cvss 8.4epss 0.00

    Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R6900P before…

  • CVE-2017-18852HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF and authentication bypass. This affects R7300DST before 1.0.0.54, R8300 before 1.0.2.100_1.0.82, R8500 before 1.0.2.100_1.0.82, and WNDR3400v3 before 1.0.1.14.

  • CVE-2020-5569HigApr 20, 2020
    risk 0.55cvss 8.4epss 0.00

    An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM…

  • CVE-2020-11886HigApr 17, 2020
    risk 0.53cvss 8.1epss 0.01

    OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Meridian 2019 before 2019.1.4, Meridian 2018 before 2018.1.16, and Meridian 2017…

  • CVE-2020-11885HigApr 17, 2020
    risk 0.47cvss 7.2epss 0.01

    WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

  • CVE-2020-0082HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead to local escalation of privilege to system_server with no additional execution privileges needed. User interaction is not needed…

  • CVE-2020-0081HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0…

  • CVE-2020-0080HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlaying other apps without the notification icon that it's overlaying. This could lead to local escalation of privilege with User execution privileges needed. User…

  • CVE-2020-0079HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…

  • CVE-2020-0078HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-7085HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.01

    A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution on a system running it.

  • CVE-2020-7082HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.02

    A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.

  • CVE-2020-7081HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.01

    A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system running it.

  • CVE-2020-7080HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitrary code execution on a system running it.

  • CVE-2020-7079HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files.

  • CVE-2020-11877HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.02

    airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code

  • CVE-2020-11876HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.02

    airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code

  • CVE-2020-9523HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.01

    Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user…

  • CVE-2020-4277HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.

  • CVE-2020-11875HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-200001 (February 2020).

  • CVE-2020-11874HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory Reset Protection (FRP). The LG ID is LVE-SMP-200004 (March 2020).

  • CVE-2019-20773HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).

  • CVE-2019-20771HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService allows unconfirmed configuration changes via a modified OMACP message. The LG ID is LVE-SMP-190006 (August 2019).

  • CVE-2019-20770HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buffer overflow that leads to arbitrary code execution. The LG ID is LVE-SMP-190013 (September 2019).

  • CVE-2019-20769HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2019).

  • CVE-2020-11793HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.03

    A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).

  • CVE-2020-10947HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.02

    Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.

  • CVE-2020-10813HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet.

  • CVE-2020-11872HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.01

    The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests before an AES-256-GCM key rotation occurs.

  • CVE-2020-11868HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.02

    ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.