VYPR

CVEs

101,977 total · page 1496 of 2,040

  • CVE-2019-14021HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overrun when processing EFS filename and payload sent over diag interface due to lack of check for filename length and payload size received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2019-14018HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound array access as there is no check on carrier index passed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9607,…

  • CVE-2019-14012HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking while processing SDP messages in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2019-14009HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Out of bound memory access while processing TZ command handler due to improper input validation on response length received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-14001HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607,…

  • CVE-2019-10625HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.00

    Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8096AU,…

  • CVE-2019-10624HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int data type copied to u8 data type in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2019-10623HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.00

    Possible integer overflow can happen in host driver while processing user controlled string due to improper validation on data received. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2019-10621HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in Nicobar, QCS405, Rennell, Saipan, SC8180X,…

  • CVE-2019-10620HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, MSM8996AU,…

  • CVE-2019-10575HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in SDA845, SDM845, SDM850

  • CVE-2019-10574HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.02

    Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2019-10556HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer overflow in some cases in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2019-10547HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2020-9280HigApr 15, 2020
    risk 0.42cvss 7.5epss 0.02

    In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.…

  • CVE-2020-3273HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS). The…

  • CVE-2020-3262HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The…

  • CVE-2020-3251HigApr 15, 2020
    risk 0.62cvss 8.8epss 0.62

    Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the…

  • CVE-2020-3249HigApr 15, 2020
    risk 0.51cvss 7.5epss 0.23

    Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the…

  • CVE-2020-3240HigApr 15, 2020
    risk 0.51cvss 7.3epss 0.39

    Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the…

  • CVE-2020-3239HigApr 15, 2020
    risk 0.63cvss 8.8epss 0.74

    Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the…

  • CVE-2020-3194HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a…

  • CVE-2020-3177HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on…

  • CVE-2020-3162HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input…

  • CVE-2020-1632HigApr 15, 2020
    risk 0.56cvss 8.6epss 0.01

    In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the established BGP session, creating a Denial of…

  • CVE-2020-11666HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.03

    CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.

  • CVE-2020-11662HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.

  • CVE-2020-11661HigApr 15, 2020
    risk 0.53cvss 8.1epss 0.02

    CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.

  • CVE-2019-20681HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.68, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6050 before 1.0.1.18, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700v2 before…

  • CVE-2019-20680HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before…

  • CVE-2019-12520HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the…

  • CVE-2020-10615HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied data, prior to copying it to a fixed-length stack-based…

  • CVE-2020-10613HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.02

    Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure.…

  • CVE-2019-20659HigApr 15, 2020
    risk 0.47cvss 7.2epss 0.02

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

  • CVE-2019-20657HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.28, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.24, JR6150 before 1.0.1.24, R6120 before…

  • CVE-2019-20656HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by a hardcoded password. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.24, JR6150 before 1.0.1.24, R6120 before 1.0.0.48, R6220 before…

  • CVE-2019-20655HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.

  • CVE-2019-20654HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

  • CVE-2020-5350HigApr 15, 2020
    risk 0.52cvss 7.9epss 0.02

    Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to…

  • CVE-2020-11792HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.

  • CVE-2020-11788HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.68, PR2000 before 1.0.0.28, R6050 before 1.0.1.18, JR6150 before 1.0.1.18, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6260 before…

  • CVE-2019-20650HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR500 before 2.3.2.56, and XR700 before 1.0.1.20.

  • CVE-2019-20649HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information.

  • CVE-2019-20643HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information.

  • CVE-2019-20642HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass.

  • CVE-2019-20641HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level.

  • CVE-2019-20640HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38,…

  • CVE-2020-10639HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could cause a buffer overflow when loaded by the affected product.

  • CVE-2020-0600HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper buffer restrictions in firmware for some Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0598HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the installer for the Intel(R) Binary Configuration Tool for Windows, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.