VYPR

CVEs

101,977 total · page 1527 of 2,040

  • CVE-2020-8947HigFeb 12, 2020
    risk 0.52cvss 7.2epss 0.22

    functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.

  • CVE-2020-8946HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.02

    Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.

  • CVE-2020-8945HigFeb 12, 2020
    risk 0.42cvss 7.5epss 0.05

    The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

  • CVE-2014-3860HigFeb 12, 2020
    risk 0.51cvss 7.8epss 0.01

    Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability

  • CVE-2013-7286HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.01

    MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm

  • CVE-2020-7046HigFeb 12, 2020
    risk 0.53cvss 7.5epss 0.51

    lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

  • CVE-2012-0951HigFeb 12, 2020
    risk 0.51cvss 7.8epss 0.00

    A Memory Corruption Vulnerability exists in NVIDIA Graphics Drivers 29549 due to an unknown function in the file proc/driver/nvidia/registry.

  • CVE-2011-4661HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.01

    A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (aka CSCtu52820), when configured with Cisco ISR Web Security with Cisco ScanSafe and User Authenticaiton NTLM configured.

  • CVE-2019-4427HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.00

    IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside. IBM X-Force ID: 162773.

  • CVE-2013-4090HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.01

    Varnish HTTP cache before 3.0.4: ACL bug

  • CVE-2013-3685HigFeb 12, 2020
    risk 0.46cvss 7.0epss 0.00

    A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.

  • CVE-2013-3494HigFeb 12, 2020
    risk 0.51cvss 7.8epss 0.02

    A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code.

  • CVE-2013-2097HigFeb 12, 2020
    risk 0.56cvss 7.8epss 0.26

    ZPanel through 10.1.0 has Remote Command Execution

  • CVE-2013-1924HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.01

    Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2

  • CVE-2020-8815HigFeb 12, 2020
    risk 0.00cvss 7.5epss 0.02

    Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of small packets.

  • CVE-2020-8595HigFeb 12, 2020
    risk 0.48cvss 7.3epss 0.03

    Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting…

  • CVE-2020-2123HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.02

    Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2020-2121HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.03

    Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2020-2120HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2116HigFeb 12, 2020
    risk 0.00cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2020-2115HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2114HigFeb 12, 2020
    risk 0.42cvss 7.5epss 0.01

    Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2020-2110HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

  • CVE-2020-2109HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.

  • CVE-2019-19921HigFeb 12, 2020
    risk 0.39cvss 7.0epss 0.00

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This…

  • CVE-2019-19194HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.01

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0, TLSR823x through 1.3.0, and TLSR826x through 3.3 devices installs a zero long term key (LTK) if an out-of-order…

  • CVE-2014-4607HigFeb 12, 2020
    risk 0.58cvss 8.8epss 0.05

    Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

  • CVE-2014-2560HigFeb 12, 2020
    risk 0.52cvss 7.5epss 0.02

    The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

  • CVE-2009-5140HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.01

    The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

  • CVE-2009-5139HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.00

    The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

  • CVE-2015-7508HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.03

    Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.

  • CVE-2014-6262HigFeb 12, 2020
    risk 0.42cvss 7.5epss 0.07

    Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph…

  • CVE-2014-4968HigFeb 12, 2020
    risk 0.61cvss 8.8epss 0.06

    The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636.

  • CVE-2020-8893HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.

  • CVE-2020-8892HigFeb 12, 2020
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.

  • CVE-2020-0792HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0745.

  • CVE-2020-0767HigFeb 11, 2020
    risk 0.01cvss 7.5epss 0.18

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712,…

  • CVE-2020-0759HigFeb 11, 2020
    risk 0.58cvss 8.8epss 0.15

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

  • CVE-2020-0757HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka 'Windows SSH Elevation of Privilege Vulnerability'.

  • CVE-2020-0754HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753.

  • CVE-2020-0753HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754.

  • CVE-2020-0752HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0667, CVE-2020-0735.

  • CVE-2020-0750HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742,…

  • CVE-2020-0749HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742,…

  • CVE-2020-0747HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0659.

  • CVE-2020-0745HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0792.

  • CVE-2020-0743HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742,…

  • CVE-2020-0742HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0743,…

  • CVE-2020-0741HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0742, CVE-2020-0743,…

  • CVE-2020-0740HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0741, CVE-2020-0742, CVE-2020-0743,…