VYPR

CVEs

101,977 total · page 1529 of 2,040

  • CVE-2020-0666HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0667, CVE-2020-0735, CVE-2020-0752.

  • CVE-2020-0665HigFeb 11, 2020
    risk 0.53cvss 8.1epss 0.04

    An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

  • CVE-2020-0662HigFeb 11, 2020
    risk 0.58cvss 8.8epss 0.13

    A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.

  • CVE-2020-0660HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.05

    A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

  • CVE-2020-0659HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0747.

  • CVE-2020-0657HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

  • CVE-2020-0655HigFeb 11, 2020
    risk 0.57cvss 8.0epss 0.66

    A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

  • CVE-2020-0618HigKEVFeb 11, 2020
    risk 0.80cvss 8.8epss 0.99

    A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

  • CVE-2020-6069HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG jpegread precision parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to…

  • CVE-2020-6067HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFF tifread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted TIFF file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a…

  • CVE-2020-6066HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG SOFx parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed…

  • CVE-2020-6065HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to…

  • CVE-2020-6064HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs…

  • CVE-2020-6063HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs…

  • CVE-2020-1942HigFeb 11, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and…

  • CVE-2013-4225HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content"…

  • CVE-2020-1711HigFeb 11, 2020
    risk 0.50cvss 7.7epss 0.04

    An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote…

  • CVE-2013-2120HigFeb 11, 2020
    risk 0.55cvss 8.4epss 0.01

    The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

  • CVE-2013-5582HigFeb 11, 2020
    risk 0.54cvss 7.8epss 0.04

    Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.

  • CVE-2020-8429HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated attacker to run remote code on the underlying operating system. The logFile…

  • CVE-2020-5823HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may…

  • CVE-2020-5822HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may…

  • CVE-2020-5821HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, which is a type of issue whereby an individual attempts to…

  • CVE-2020-5820HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may…

  • CVE-2013-3942HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability

  • CVE-2013-0517HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.

  • CVE-2014-9748HigFeb 11, 2020
    risk 0.46cvss 8.1epss 0.03

    The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or possibly have unspecified other impact by…

  • CVE-2014-6447HigFeb 11, 2020
    risk 0.46cvss 7.1epss 0.01

    Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before…

  • CVE-2019-13946HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that…

  • CVE-2019-13941HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web Server use predictable path names for project files that legitimately authenticated users have created by using the application's export…

  • CVE-2019-13926HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port…

  • CVE-2019-13925HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port…

  • CVE-2013-4535HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.

  • CVE-2020-6417HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local attacker to execute arbitrary code via a crafted registry entry.

  • CVE-2020-6416HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6415HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6414HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6413HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.

  • CVE-2020-6410HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted domain name.

  • CVE-2020-6409HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to bypass navigation restrictions via a crafted domain name.

  • CVE-2020-6406HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6404HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6402HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.03

    Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

  • CVE-2020-6398HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2020-6390HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.03

    Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6389HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

  • CVE-2020-6388HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6387HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

  • CVE-2020-6385HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2020-6382HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.