VYPR

CVEs

101,977 total · page 1536 of 2,040

  • CVE-2019-16022HigJan 26, 2020
    risk 0.56cvss 8.6epss 0.01

    Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect…

  • CVE-2019-16020HigJan 26, 2020
    risk 0.56cvss 8.6epss 0.01

    Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect…

  • CVE-2019-16005HigJan 26, 2020
    risk 0.47cvss 7.2epss 0.04

    A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management…

  • CVE-2019-15989HigJan 26, 2020
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the implementation of the Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update…

  • CVE-2019-12629HigJan 26, 2020
    risk 0.47cvss 7.2epss 0.02

    A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for…

  • CVE-2020-7596HigJan 25, 2020
    risk 0.57cvss 8.8epss 0.02

    Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.

  • CVE-2012-6613HigJan 25, 2020
    risk 0.47cvss 7.2epss 0.02

    D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

  • CVE-2012-6345HigJan 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.

  • CVE-2019-5147HigJan 25, 2020
    risk 0.56cvss 8.6epss 0.02

    An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability…

  • CVE-2019-5146HigJan 25, 2020
    risk 0.56cvss 8.6epss 0.02

    An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13025.10004. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability…

  • CVE-2019-5124HigJan 25, 2020
    risk 0.56cvss 8.6epss 0.02

    An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability…

  • CVE-2015-9541HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

  • CVE-2014-9630HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or…

  • CVE-2014-9629HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.

  • CVE-2014-9628HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.

  • CVE-2014-9627HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other…

  • CVE-2014-9626HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.

  • CVE-2014-9625HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a…

  • CVE-2019-1414HigJan 24, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'.

  • CVE-2019-1354HigJan 24, 2020
    risk 0.59cvss 8.8epss 0.22

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.

  • CVE-2019-1352HigJan 24, 2020
    risk 0.59cvss 8.8epss 0.24

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1351HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.09

    A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.

  • CVE-2019-1350HigJan 24, 2020
    risk 0.59cvss 8.8epss 0.26

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1349HigJan 24, 2020
    risk 0.60cvss 8.8epss 0.34

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

  • CVE-2013-1598HigJan 24, 2020
    risk 0.62cvss 8.8epss 0.20

    A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.

  • CVE-2019-19363HigJan 24, 2020
    risk 0.54cvss 7.8epss 0.05

    An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version…

  • CVE-2015-2929HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.01

    The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.

  • CVE-2015-2928HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.01

    The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.

  • CVE-2015-2689HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.

  • CVE-2015-2688HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.

  • CVE-2015-1530HigJan 24, 2020
    risk 0.51cvss 7.8epss 0.00

    media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.

  • CVE-2020-6964HigJan 24, 2020
    risk 0.56cvss 8.6epss 0.01

    In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for…

  • CVE-2015-4041HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow…

  • CVE-2014-1923HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via…

  • CVE-2014-1922HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2013-1594HigJan 24, 2020
    risk 0.52cvss 7.5epss 0.07

    An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.

  • CVE-2020-5219HigJan 24, 2020
    risk 0.50cvss 8.7epss 0.02

    Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-expressions in the browser, an attacker could run any browser…

  • CVE-2019-19631HigJan 24, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. A…

  • CVE-2020-7226HigJan 24, 2020
    risk 0.42cvss 7.5epss 0.03

    CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of…

  • CVE-2012-6302HigJan 24, 2020
    risk 0.51cvss 7.8epss 0.00

    Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.

  • CVE-2019-3699HigJan 24, 2020
    risk 0.50cvss 7.7epss 0.00

    UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE…

  • CVE-2019-3697HigJan 24, 2020
    risk 0.50cvss 7.7epss 0.01

    UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.

  • CVE-2019-3694HigJan 24, 2020
    risk 0.50cvss 7.7epss 0.00

    A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2.0.49-4.2 and prior versions. openSUSE Leap 15.1 munin…

  • CVE-2019-3693HigJan 24, 2020
    risk 0.50cvss 7.7epss 0.00

    A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to…

  • CVE-2019-3692HigJan 24, 2020
    risk 0.50cvss 7.7epss 0.01

    The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE…

  • CVE-2020-6007HigJan 23, 2020
    risk 0.52cvss 7.9epss 0.02

    Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.

  • CVE-2012-6663HigJan 23, 2020
    risk 0.53cvss 7.5epss 0.09

    General Electric D20ME devices are not properly configured and reveal plaintext passwords.

  • CVE-2012-5389HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.07

    NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request.

  • CVE-2012-5340HigJan 23, 2020
    risk 0.54cvss 7.8epss 0.06

    SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.

  • CVE-2012-4606HigJan 23, 2020
    risk 0.51cvss 7.8epss 0.00

    Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.