VYPR

CVEs

101,977 total · page 1524 of 2,040

  • CVE-2012-5363HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.03

    The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.

  • CVE-2012-5362HigFeb 20, 2020
    risk 0.50cvss 7.5epss 0.15

    The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2010-4669.

  • CVE-2020-9308HigFeb 20, 2020
    risk 0.00cvss 8.8epss 0.02

    archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.

  • CVE-2012-2629HigFeb 20, 2020
    risk 0.60cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to…

  • CVE-2020-3945HigFeb 19, 2020
    risk 0.49cvss 7.5epss 0.01

    vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote…

  • CVE-2020-3944HigFeb 19, 2020
    risk 0.56cvss 8.6epss 0.01

    vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running,…

  • CVE-2015-7747HigFeb 19, 2020
    risk 0.51cvss 8.8epss 0.09

    Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by…

  • CVE-2020-3114HigFeb 19, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2020-3112HigFeb 19, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privileges on the application. The vulnerability is due to insufficient access control validation. An attacker could exploit this…

  • CVE-2019-1950HigFeb 19, 2020
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker…

  • CVE-2020-6062HigFeb 19, 2020
    risk 0.49cvss 7.5epss 0.06

    An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.

  • CVE-2012-0055HigFeb 19, 2020
    risk 0.54cvss 7.8epss 0.01

    OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

  • CVE-2020-8959HigFeb 19, 2020
    risk 0.51cvss 7.8epss 0.00

    Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.

  • CVE-2019-12437HigFeb 19, 2020
    risk 0.50cvss 8.8epss 0.01

    In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,

  • CVE-2020-4204HigFeb 19, 2020
    risk 0.51cvss 7.8epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force…

  • CVE-2020-4135HigFeb 19, 2020
    risk 0.49cvss 7.5epss 0.03

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.

  • CVE-2012-6685HigFeb 19, 2020
    risk 0.49cvss 7.5epss 0.02

    Nokogiri before 1.5.4 is vulnerable to XXE attacks

  • CVE-2012-6614HigFeb 19, 2020
    risk 0.47cvss 7.2epss 0.03

    D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.

  • CVE-2018-16994HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth contain technology from Phoenix…

  • CVE-2020-9270HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.

  • CVE-2020-9269HigFeb 18, 2020
    risk 0.47cvss 7.2epss 0.02

    SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.

  • CVE-2020-9268HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.01

    SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.

  • CVE-2020-9265HigFeb 18, 2020
    risk 0.53cvss 8.2epss 0.01

    phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.

  • CVE-2015-7507HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.

  • CVE-2015-7505HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.03

    Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.

  • CVE-2019-18352HigFeb 18, 2020
    risk 0.53cvss 8.2epss 0.00

    Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices before V2.90 when using MAC-based port security.

  • CVE-2020-6844HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.

  • CVE-2013-4227HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a…

  • CVE-2020-5530HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2020-8011HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (controller) component. A remote attacker can crash the Controller service.

  • CVE-2020-1812HigFeb 18, 2020
    risk 0.51cvss 7.8epss 0.01

    HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick the user into installing a malicious application to exploit this vulnerability.…

  • CVE-2020-1790HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain…

  • CVE-2020-1816HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Denial of Service (DoS) vulnerability. Due to improper processing of specific IPSEC…

  • CVE-2020-1815HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a memory leak vulnerability. The software does not sufficiently track and release…

  • CVE-2020-1811HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker…

  • CVE-2015-8751HigFeb 17, 2020
    risk 0.57cvss 8.8epss 0.03

    Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

  • CVE-2020-1856HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C60, and V500R005C00 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected…

  • CVE-2020-1841HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R002C00SPC900; and TE60 versions V500R002C00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C10, V600R019C00, and V600R019C00SPC100 have an…

  • CVE-2020-1829HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 have a vulnerability that the IPSec module handles a message improperly. Attackers can send specific message to cause…

  • CVE-2020-1827HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. An attacker can exploit this…

  • CVE-2014-1947HigFeb 17, 2020
    risk 0.54cvss 7.8epss 0.07

    Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a…

  • CVE-2020-1858HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace USG6600 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100; and USG9500 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have a denial of…

  • CVE-2020-1828HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in…

  • CVE-2020-1693HigFeb 17, 2020
    risk 0.00cvss 8.6epss 0.04

    A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain…

  • CVE-2019-10790HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.02

    taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB.…

  • CVE-2020-7597HigFeb 17, 2020
    risk 0.50cvss 8.8epss 0.03

    codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.

  • CVE-2019-18998HigFeb 17, 2020
    risk 0.46cvss 7.1epss 0.01

    Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

  • CVE-2015-0258HigFeb 17, 2020
    risk 0.51cvss 8.8epss 0.04

    Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.

  • CVE-2020-9043HigFeb 17, 2020
    risk 0.58cvss 8.8epss 0.08

    The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.

  • CVE-2020-1704HigFeb 17, 2020
    risk 0.46cvss 7.0epss 0.00

    An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and…