VYPR

CVEs

101,977 total · page 1548 of 2,040

  • CVE-2019-12418HigDec 23, 2019
    risk 0.46cvss 7.0epss 0.01

    When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle…

  • CVE-2019-6682HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resources when processing certain types of HTTP responses from the origin web server. This vulnerability is only known to affect…

  • CVE-2019-6677HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, under certain conditions when using custom TCP congestion control settings in a TCP profile, TMM stops processing traffic when processed by an iRule.

  • CVE-2019-6676HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.

  • CVE-2019-17563HigDec 23, 2019
    risk 0.50cvss 7.5epss 0.11

    When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the…

  • CVE-2019-18390HigDec 23, 2019
    risk 0.39cvss 7.1epss 0.00

    An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.

  • CVE-2019-18389HigDec 23, 2019
    risk 0.44cvss 7.8epss 0.00

    A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.

  • CVE-2019-19931HigDec 23, 2019
    risk 0.57cvss 8.8epss 0.01

    In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.

  • CVE-2019-19929HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.01

    An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.

  • CVE-2019-19926HigDec 23, 2019
    risk 0.01cvss 7.5epss 0.07

    multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

  • CVE-2019-19920HigDec 22, 2019
    risk 0.57cvss 8.8epss 0.03

    sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

  • CVE-2019-16786HigDec 20, 2019
    risk 0.39cvss 7.1epss 0.03

    Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma…

  • CVE-2019-16785HigDec 20, 2019
    risk 0.39cvss 7.1epss 0.03

    Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if…

  • CVE-2019-19231HigDec 20, 2019
    risk 0.47cvss 7.3epss 0.01

    An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.

  • CVE-2019-19918HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

  • CVE-2019-19917HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

  • CVE-2019-15915HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

  • CVE-2019-15914HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

  • CVE-2019-15912HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

  • CVE-2019-15910HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

  • CVE-2018-1934HigDec 20, 2019
    risk 0.57cvss 8.8epss 0.00

    IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153179.

  • CVE-2019-19693HigDec 20, 2019
    risk 0.46cvss 7.1epss 0.01

    The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute…

  • CVE-2012-6111HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.02

    gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

  • CVE-2012-3409HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.00

    ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

  • CVE-2019-19141HigDec 19, 2019
    risk 0.58cvss 8.8epss 0.04

    The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server has permissions. This allows remote code execution via a variety of methods, such as (on a default…

  • CVE-2019-19340HigDec 19, 2019
    risk 0.53cvss 8.2epss 0.02

    A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active,…

  • CVE-2019-19234HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software…

  • CVE-2019-19232HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a…

  • CVE-2019-8254HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-8253HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-19909HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.

  • CVE-2019-18181HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.00

    In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated…

  • CVE-2019-19906HigDec 19, 2019
    risk 0.42cvss 7.5epss 0.08

    cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

  • CVE-2019-17633HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.01

    For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local…

  • CVE-2019-16465HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…

  • CVE-2019-11780HigDec 19, 2019
    risk 0.53cvss 8.1epss 0.02

    Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

  • CVE-2019-16461HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…

  • CVE-2019-16458HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…

  • CVE-2019-16457HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…

  • CVE-2019-16456HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…

  • CVE-2019-16449HigDec 19, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…

  • CVE-2019-19902HigDec 19, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing…

  • CVE-2019-7487HigDec 19, 2019
    risk 0.51cvss 7.8epss 0.00

    Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

  • CVE-2019-7486HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.

  • CVE-2019-7485HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

  • CVE-2019-7483HigKEVDec 19, 2019
    risk 0.61cvss 7.5epss 0.04

    In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

  • CVE-2019-17390HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Outlook add-in in Pronestor Planner before 8.1.77. There is local privilege escalation in the Health Monitor service because PronestorHealthMonitor.exe access control is mishandled, aka PNB-2359.

  • CVE-2019-11147HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo software for Intel(R) TXE before versions 3.1.70 and 4.0.20; INTEL-SA-00086 Detection Tool version…

  • CVE-2019-11132HigDec 18, 2019
    risk 0.55cvss 8.4epss 0.01

    Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2019-11104HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local…