VYPR

CVEs

101,972 total · page 1554 of 2,040

  • CVE-2019-16732HigDec 13, 2019
    risk 0.53cvss 8.1epss 0.01

    Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user.

  • CVE-2019-16731HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings.

  • CVE-2019-19793HigDec 13, 2019
    risk 0.57cvss 8.8epss 0.01

    In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges.

  • CVE-2019-19774HigDec 13, 2019
    risk 0.61cvss 8.8epss 0.13

    An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing…

  • CVE-2019-17123HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment…

  • CVE-2019-19787HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.

  • CVE-2019-19786HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.

  • CVE-2019-19785HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.

  • CVE-2019-5250HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application…

  • CVE-2019-5248HigDec 13, 2019
    risk 0.48cvss 7.4epss 0.00

    CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on…

  • CVE-2019-19397HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. Attackers may exploit the vulnerability to cause information leaks.

  • CVE-2014-3495HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    duplicity 0.6.24 has improper verification of SSL certificates

  • CVE-2014-1867HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.00

    suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

  • CVE-2019-19501HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.00

    VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe.

  • CVE-2019-18838HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to…

  • CVE-2019-13347HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled…

  • CVE-2014-0212HigDec 13, 2019
    risk 0.49cvss 7.5epss 0.03

    qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

  • CVE-2014-0197HigDec 13, 2019
    risk 0.57cvss 8.8epss 0.01

    CFME: CSRF protection vulnerability via permissive check of the referrer header

  • CVE-2019-19778HigDec 13, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.

  • CVE-2019-19777HigDec 13, 2019
    risk 0.57cvss 8.8epss 0.01

    stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.

  • CVE-2019-16777HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.02

    Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any…

  • CVE-2019-16776HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.03

    Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher…

  • CVE-2019-16775HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.03

    Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would…

  • CVE-2019-12420HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.07

    In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.

  • CVE-2019-5144HigDec 12, 2019
    risk 0.53cvss 8.1epss 0.02

    An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file…

  • CVE-2019-19771HigDec 12, 2019
    risk 0.57cvss 8.8epss 0.01

    The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.

  • CVE-2019-19770HigDec 12, 2019
    risk 0.53cvss 8.2epss 0.02

    In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file). NOTE:…

  • CVE-2019-19768HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.04

    In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).

  • CVE-2019-19766HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    The Bitwarden server through 1.32.0 has a potentially unwanted KDF.

  • CVE-2019-18338HigDec 12, 2019
    risk 0.50cvss 7.7epss 0.03

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An…

  • CVE-2019-18320HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please note that an attacker needs to have…

  • CVE-2019-18319HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18318HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server can cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18317HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18311HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent…

  • CVE-2019-18310HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent…

  • CVE-2019-18309HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a low privileged user account could gain root privileges by manipulating specific files in the local file system. This vulnerability…

  • CVE-2019-18308HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a low privileged user account could gain root privileges by manipulating specific files in the local file system. This vulnerability…

  • CVE-2019-18307HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.03

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18306HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18305HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.03

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18304HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.03

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18303HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18302HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18301HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18300HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18299HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18298HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18297HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and low privileges could gain root privileges by sending specifically crafted packets to a named pipe. Please note that an attacker needs…

  • CVE-2019-18294HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…