VYPR

CVEs

101,977 total · page 1533 of 2,040

  • CVE-2019-18193HigFeb 3, 2020
    risk 0.49cvss 7.5epss 0.00

    In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0.

  • CVE-2020-3927HigFeb 3, 2020
    risk 0.54cvss 8.3epss 0.01

    An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.

  • CVE-2020-3925HigFeb 3, 2020
    risk 0.54cvss 8.3epss 0.03

    A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.

  • CVE-2014-8141HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

  • CVE-2014-8321HigJan 31, 2020
    risk 0.44cvss 7.8epss 0.01

    Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.

  • CVE-2014-8140HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

  • CVE-2014-8139HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

  • CVE-2014-8126HigJan 31, 2020
    risk 0.57cvss 8.8epss 0.03

    The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

  • CVE-2014-5236HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.04

    Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument…

  • CVE-2014-3868HigJan 31, 2020
    risk 0.53cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in ZeusCart 4.x.

  • CVE-2014-3119HigJan 31, 2020
    risk 0.53cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search_string parameter in the contacts module to index.php or allow remote attackers to execute arbitrary SQL commands via the…

  • CVE-2019-13000HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "it is beta-quality software and don't put too much money in it."

  • CVE-2019-12999HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.

  • CVE-2019-12998HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."

  • CVE-2016-2032HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672

  • CVE-2013-3489HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.03

    Buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0 allows remote attackers to execute arbitrary code via a crafted RealMedia .rm file

  • CVE-2013-3488HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.03

    Stack-based buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0.7858 allows remote attackers to execute arbitrary code via a crafted MPEG-2 Transport Stream (M2TS) file.

  • CVE-2011-4117HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.01

    The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

  • CVE-2011-4115HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

  • CVE-2011-4088HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    ABRT might allow attackers to obtain sensitive information from crash reports.

  • CVE-2019-4720HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.

  • CVE-2013-5116HigJan 31, 2020
    risk 0.46cvss 7.1epss 0.00

    Evernote prior to 5.5.1 has insecure password change

  • CVE-2019-19550HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL.

  • CVE-2013-3322HigJan 31, 2020
    risk 0.47cvss 7.2epss 0.04

    NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.

  • CVE-2020-7914HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.

  • CVE-2020-7219HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.02

    HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.

  • CVE-2020-7218HigJan 31, 2020
    risk 0.00cvss 7.5epss 0.01

    HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.

  • CVE-2020-5232HigJan 31, 2020
    risk 0.50cvss 8.7epss 0.01

    A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry.

  • CVE-2020-8495HigJan 30, 2020
    risk 0.52cvss 7.5epss 0.03

    In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate,…

  • CVE-2020-8494HigJan 30, 2020
    risk 0.57cvss 8.8epss 0.01

    In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an attacker with Timekeeper, Master Timekeeper, or HR Admin privileges to gain unauthorized administrative privileges within the application via…

  • CVE-2020-5206HigJan 30, 2020
    risk 0.50cvss 8.7epss 0.01

    In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an…

  • CVE-2020-5230HigJan 30, 2020
    risk 0.43cvss 7.7epss 0.01

    Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape…

  • CVE-2019-20358HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.05

    Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to…

  • CVE-2015-8851HigJan 30, 2020
    risk 0.42cvss 7.5epss 0.02

    node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

  • CVE-2015-0949HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.00

    The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, which allows local users to…

  • CVE-2020-5229HigJan 30, 2020
    risk 0.43cvss 7.7epss 0.01

    Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of a random salt, causing hashes for users with the same username and password to collide which is…

  • CVE-2020-5228HigJan 30, 2020
    risk 0.49cvss 7.6epss 0.01

    Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly…

  • CVE-2020-3147HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web interface. An attacker…

  • CVE-2020-7909HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

  • CVE-2020-7906HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

  • CVE-2020-7905HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

  • CVE-2020-7904HigJan 30, 2020
    risk 0.48cvss 7.4epss 0.01

    In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

  • CVE-2020-1931HigJan 30, 2020
    risk 0.53cvss 8.1epss 0.06

    A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts to exploit the issue will throw warnings.…

  • CVE-2020-1930HigJan 30, 2020
    risk 0.53cvss 8.1epss 0.07

    A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpatched, exploits can be injected in a number of scenarios…

  • CVE-2013-1352HigJan 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.

  • CVE-2013-0725HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.00

    ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities

  • CVE-2013-0291HigJan 30, 2020
    risk 0.53cvss 7.5epss 0.16

    NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability

  • CVE-2020-8442HigJan 30, 2020
    risk 0.57cvss 8.8epss 0.02

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.

  • CVE-2020-8438HigJan 29, 2020
    risk 0.47cvss 7.2epss 0.02

    Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

  • CVE-2013-3321HigJan 29, 2020
    risk 0.49cvss 7.5epss 0.02

    NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.