VYPR

CVEs

101,977 total · page 1531 of 2,040

  • CVE-2013-2009HigFeb 7, 2020
    risk 0.61cvss 8.8epss 0.13

    WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution

  • CVE-2013-1202HigFeb 7, 2020
    risk 0.49cvss 7.5epss 0.01

    Cisco ACE A2(3.6) allows log retention DoS.

  • CVE-2012-1567HigFeb 7, 2020
    risk 0.49cvss 7.5epss 0.01

    LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate.

  • CVE-2012-1566HigFeb 7, 2020
    risk 0.49cvss 7.5epss 0.01

    LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny.

  • CVE-2019-14088HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Possible use after free issue while CRM is accessing the link pointer from device private data due to lack of resource protection in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2019-14060HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Uninitialized stack data gets used If memory is not allocated for blob or if the allocated blob is less than the struct size required due to lack of check of return value for read or write blob in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2019-14055HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2019-14051HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Subsequent additions performed during Module loading while allocating the memory would lead to integer overflow and then to buffer overflow in Snapdragon Industrial IOT in MDM9206, MDM9607

  • CVE-2019-14049HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2019-14046HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Out of bound access while allocating memory for an array in camera due to improper validation of elements parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-14044HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    Out of bound access due to access of uninitialized memory segment in an array of pointers while normal camera open close in Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SDM439, SDM630, SDM636, SDM660, SDX24

  • CVE-2019-14041HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer with physical address information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2019-14040HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.01

    Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2019-14002HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU,…

  • CVE-2019-10567HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.00

    There is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existing commands could allow unintended GPU opcodes to be executed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2020-8655HigKEVFeb 7, 2020
    risk 0.70cvss 7.8epss 0.60

    An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root via a crafted NSE script for nmap 7.

  • CVE-2020-8654HigFeb 7, 2020
    risk 0.67cvss 8.8epss 0.86

    An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

  • CVE-2013-3638HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.

  • CVE-2013-3568HigFeb 6, 2020
    risk 0.62cvss 8.8epss 0.25

    Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

  • CVE-2020-5319HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.01

    Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit…

  • CVE-2020-5318HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.01

    Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebDAV file-serving components have a vulnerability wherein…

  • CVE-2012-6309HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service.

  • CVE-2012-6307HigFeb 6, 2020
    risk 0.61cvss 8.8epss 0.06

    A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary code

  • CVE-2012-6297HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.02

    Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.

  • CVE-2020-7954HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by default allows the execution of programs (e.g. nmap) without…

  • CVE-2020-7953HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.

  • CVE-2020-7920HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.02

    pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.

  • CVE-2020-6767HigFeb 6, 2020
    risk 0.50cvss 7.7epss 0.01

    A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5…

  • CVE-2020-5856HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.

  • CVE-2019-15711HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.01

    A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

  • CVE-2014-2030HigFeb 6, 2020
    risk 0.61cvss 8.8epss 0.11

    Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different…

  • CVE-2014-1958HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.04

    Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.

  • CVE-2013-4572HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.02

    The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

  • CVE-2013-4166HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.02

    The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and…

  • CVE-2016-9928HigFeb 6, 2020
    risk 0.48cvss 7.4epss 0.05

    MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

  • CVE-2015-6000HigFeb 6, 2020
    risk 0.63cvss 8.8epss 0.40

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an…

  • CVE-2020-8658HigFeb 6, 2020
    risk 0.58cvss 8.8epss 0.10

    The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of…

  • CVE-2019-20406HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable…

  • CVE-2019-20400HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.

  • CVE-2019-20104HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.02

    The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.

  • CVE-2020-8648HigFeb 6, 2020
    risk 0.46cvss 7.1epss 0.01

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

  • CVE-2011-1597HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.02

    OpenVAS Manager v2.0.3 allows plugin remote code execution.

  • CVE-2020-8641HigFeb 5, 2020
    risk 0.58cvss 8.8epss 0.11

    Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.

  • CVE-2013-2680HigFeb 5, 2020
    risk 0.52cvss 7.5epss 0.09

    Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.

  • CVE-2011-0525HigFeb 5, 2020
    risk 0.57cvss 8.8epss 0.01

    Batavi before 1.0 has CSRF.

  • CVE-2010-5304HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.03

    A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.

  • CVE-2020-3123HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds…

  • CVE-2020-3119HigFeb 5, 2020
    risk 0.58cvss 8.8epss 0.05

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does…

  • CVE-2020-3118HigKEVFeb 5, 2020
    risk 0.70cvss 8.8epss 0.12

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from…

  • CVE-2020-3111HigFeb 5, 2020
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when…