VYPR

CVEs

101,977 total · page 1532 of 2,040

  • CVE-2020-3110HigFeb 5, 2020
    risk 0.58cvss 8.8epss 0.06

    A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing…

  • CVE-2015-0102HigFeb 5, 2020
    risk 0.53cvss 8.1epss 0.02

    IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

  • CVE-2020-6833HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

  • CVE-2019-12180HigFeb 5, 2020
    risk 0.51cvss 7.8epss 0.05

    An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim…

  • CVE-2019-11516HigFeb 5, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Extended Inquiry Responses (EIRs) are improperly handled, which causes a heap-based buffer overflow during device inquiry. This overflow can be used to overwrite…

  • CVE-2020-8507HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.

  • CVE-2020-7978HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

  • CVE-2020-7972HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

  • CVE-2020-7969HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

  • CVE-2020-7968HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

  • CVE-2020-7966HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.02

    GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

  • CVE-2019-4613HigFeb 5, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.

  • CVE-2019-16204HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an external server.

  • CVE-2019-16203HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.

  • CVE-2013-0507HigFeb 5, 2020
    risk 0.53cvss 8.1epss 0.01

    IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability

  • CVE-2020-7216HigFeb 5, 2020
    risk 0.49cvss 7.5epss 0.01

    An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.

  • CVE-2020-5237HigFeb 5, 2020
    risk 0.51cvss 8.8epss 0.04

    Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to…

  • CVE-2020-5208HigFeb 5, 2020
    risk 0.43cvss 7.7epss 0.03

    It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is…

  • CVE-2019-12528HigFeb 4, 2020
    risk 0.50cvss 7.5epss 0.10

    An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

  • CVE-2015-2802HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.06

    An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive…

  • CVE-2020-8517HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process…

  • CVE-2020-8450HigFeb 4, 2020
    risk 0.53cvss 7.3epss 0.72

    An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

  • CVE-2020-8449HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • CVE-2020-8121HigFeb 4, 2020
    risk 0.53cvss 8.1epss 0.01

    A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

  • CVE-2020-8116HigFeb 4, 2020
    risk 0.41cvss 7.3epss 0.03

    Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

  • CVE-2020-6060HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.02

    A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply…

  • CVE-2020-6059HigFeb 4, 2020
    risk 0.54cvss 8.2epss 0.03

    An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information disclosure and Denial Of Service. In order to…

  • CVE-2019-15613HigFeb 4, 2020
    risk 0.52cvss 8.0epss 0.01

    A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.

  • CVE-2015-3611HigFeb 4, 2020
    risk 0.58cvss 8.8epss 0.06

    A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.

  • CVE-2020-7221HigFeb 4, 2020
    risk 0.00cvss 7.8epss 0.01

    mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect…

  • CVE-2020-4163HigFeb 4, 2020
    risk 0.47cvss 7.2epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.

  • CVE-2019-4541HigFeb 4, 2020
    risk 0.47cvss 7.2epss 0.01

    IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.

  • CVE-2019-4540HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.

  • CVE-2019-19273HigFeb 4, 2020
    risk 0.51cvss 7.8epss 0.00

    On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.

  • CVE-2019-9674HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.06

    Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

  • CVE-2013-2678HigFeb 4, 2020
    risk 0.57cvss 8.1epss 0.17

    Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.

  • CVE-2013-2676HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.02

    Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.

  • CVE-2013-7053HigFeb 4, 2020
    risk 0.60cvss 8.8epss 0.03

    D-Link DIR-100 4.03B07: cli.cgi CSRF

  • CVE-2013-7051HigFeb 4, 2020
    risk 0.61cvss 8.8epss 0.16

    D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

  • CVE-2011-4937HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.02

    Joomla! 1.7.1 has core information disclosure due to inadequate error checking.

  • CVE-2011-3629HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.01

    Joomla! core 1.7.1 allows information disclosure due to weak encryption

  • CVE-2020-3937HigFeb 4, 2020
    risk 0.53cvss 8.1epss 0.01

    SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries and access arbitrary file in the database.

  • CVE-2019-9502HigFeb 3, 2020
    risk 0.52cvss 7.9epss 0.02

    The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote,…

  • CVE-2019-9501HigFeb 3, 2020
    risk 0.52cvss 7.9epss 0.03

    The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi…

  • CVE-2016-4676HigFeb 3, 2020
    risk 0.49cvss 7.5epss 0.02

    A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.

  • CVE-2013-2674HigFeb 3, 2020
    risk 0.49cvss 7.5epss 0.03

    Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.

  • CVE-2019-16893HigFeb 3, 2020
    risk 0.55cvss 7.5epss 0.38

    The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.

  • CVE-2013-2672HigFeb 3, 2020
    risk 0.49cvss 7.5epss 0.02

    Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.

  • CVE-2013-2646HigFeb 3, 2020
    risk 0.49cvss 7.5epss 0.01

    TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.

  • CVE-2020-8545HigFeb 3, 2020
    risk 0.00cvss 7.5epss 0.01

    Global.py in AIL framework 2.8 allows path traversal.