VYPR

CVEs

101,977 total · page 1547 of 2,040

  • CVE-2015-5290HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.

  • CVE-2013-2011HigDec 26, 2019
    risk 0.58cvss 8.8epss 0.05

    WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.

  • CVE-2012-4420HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.05

    An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation).…

  • CVE-2012-3462HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

  • CVE-2019-5275HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.00

    USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a heap buffer overflow when decoding a certificate, an attacker may exploit the vulnerability by a…

  • CVE-2019-5274HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.00

    USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in an infinite loop, an attacker may exploit the vulnerability via a malicious certificate to perform a…

  • CVE-2019-5273HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.00

    USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer overrun error, an attacker may exploit the vulnerability by a malicious…

  • CVE-2019-19996HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.

  • CVE-2019-19995HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.

  • CVE-2019-16326HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.

  • CVE-2019-16789HigDec 26, 2019
    risk 0.39cvss 7.1epss 0.03

    In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests…

  • CVE-2019-6032HigDec 26, 2019
    risk 0.48cvss 7.4epss 0.01

    The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2019-6030HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-6027HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-6026HigDec 26, 2019
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to…

  • CVE-2019-6019HigDec 26, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2019-6014HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.

  • CVE-2019-6012HigDec 26, 2019
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2019-6008HigDec 26, 2019
    risk 0.51cvss 7.8epss 0.01

    An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions),…

  • CVE-2019-19681HigDec 26, 2019
    risk 0.58cvss 8.8epss 0.05

    Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in…

  • CVE-2019-15695HigDec 26, 2019
    risk 0.00cvss 7.2epss 0.04

    TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can choose offset from start of the buffer to start…

  • CVE-2019-15694HigDec 26, 2019
    risk 0.00cvss 7.2epss 0.04

    TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this vulnerability could potentially result into remote…

  • CVE-2019-15693HigDec 26, 2019
    risk 0.00cvss 7.2epss 0.04

    TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

  • CVE-2019-15692HigDec 26, 2019
    risk 0.00cvss 7.2epss 0.05

    TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be…

  • CVE-2019-15691HigDec 26, 2019
    risk 0.00cvss 7.2epss 0.05

    TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which has been already freed during the…

  • CVE-2019-19999HigDec 26, 2019
    risk 0.47cvss 7.2epss 0.02

    Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.

  • CVE-2019-19998HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.

  • CVE-2019-19979HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.

  • CVE-2019-19967HigDec 25, 2019
    risk 0.49cvss 7.5epss 0.01

    The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.

  • CVE-2019-19962HigDec 25, 2019
    risk 0.00cvss 7.5epss 0.01

    wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

  • CVE-2019-5702HigDec 24, 2019
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

  • CVE-2019-19925HigDec 24, 2019
    risk 0.01cvss 7.5epss 0.07

    zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

  • CVE-2019-19956HigDec 24, 2019
    risk 0.49cvss 7.5epss 0.06

    xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

  • CVE-2019-19923HigDec 24, 2019
    risk 0.01cvss 7.5epss 0.07

    flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

  • CVE-2019-19954HigDec 24, 2019
    risk 0.00cvss 7.3epss 0.00

    Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.

  • CVE-2019-19695HigDec 24, 2019
    risk 0.49cvss 7.5epss 0.03

    A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symbolic link to a target file and modify it.

  • CVE-2019-18211HigDec 23, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-privilege user.

  • CVE-2019-5539HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.00

    VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal…

  • CVE-2019-18236HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.03

    Multiple buffer overflow vulnerabilities exist when the PLC Editor Version 1.3.5_20190129 processes project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.

  • CVE-2019-8463HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.

  • CVE-2019-3467HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.01

    Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.

  • CVE-2019-6687HigDec 23, 2019
    risk 0.48cvss 7.4epss 0.00

    On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.

  • CVE-2019-6685HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.00

    On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, users with access to edit iRules are able to create iRules which can lead to an elevation of privilege, configuration modification, and arbitrary system…

  • CVE-2019-6684HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, under certain conditions, a multi-bladed BIG-IP Virtual Clustered Multiprocessing (vCMP) may drop broadcast packets when they are rebroadcast to the vCMP guest secondary blades. An…

  • CVE-2019-6683HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions.

  • CVE-2019-6681HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a memory leak in Multicast Forwarding Cache (MFC) handling in tmrouted.

  • CVE-2019-6680HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5, while processing traffic through a standard virtual server that targets a FastL4 virtual server (VIP on VIP), hardware appliances may stop responding.

  • CVE-2019-5276HigDec 23, 2019
    risk 0.57cvss 8.8epss 0.00

    Huawei smart phones with earlier versions than ELLE-AL00B 9.1.0.222(C00E220R2P1) have a buffer overflow vulnerability. An attacker may intercept and tamper with the packet in the local area network (LAN) to exploit this vulnerability. Successful exploitation may cause the…

  • CVE-2019-5266HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful exploit may cause the function will be disabled.

  • CVE-2019-5265HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an improper access control vulnerability. The function incorrectly controls certain access messages, attackers can simulate a sender to steal P2P network information. Successful exploit may cause information…