VYPR

CVEs

101,972 total · page 1555 of 2,040

  • CVE-2019-18292HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.03

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18291HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18290HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent…

  • CVE-2019-18288HigDec 12, 2019
    risk 0.58cvss 8.8epss 0.04

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at the RMI interface could be able to gain remote code execution through an unsecured file upload. Please note that an attacker…

  • CVE-2019-13942HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet…

  • CVE-2019-13930HigDec 12, 2019
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate…

  • CVE-2019-4606HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on…

  • CVE-2019-19248HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).

  • CVE-2019-19247HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).

  • CVE-2019-17358HigDec 12, 2019
    risk 0.46cvss 8.1epss 0.03

    Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory…

  • CVE-2019-15934HigDec 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Intesync Solismed 3.3sp has CSRF.

  • CVE-2019-2338HigDec 12, 2019
    risk 0.46cvss 7.1epss 0.00

    Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-2337HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause device to shutdown in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2019-2321HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2019-2319HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845,…

  • CVE-2019-2310HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    Out of bound read would occur while trying to read action category and action ID without validating the action length of the Rx Frame body in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…

  • CVE-2019-2288HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2019-10592HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check on the maximum mode count in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2019-10571HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2019-10555HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2019-10530HigDec 12, 2019
    risk 0.51cvss 7.8epss 0.00

    Lack of check of data truncation on user supplied data in kernel leads to buffer overflow in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650,…

  • CVE-2019-10494HigDec 12, 2019
    risk 0.53cvss 8.1epss 0.00

    Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2019-10485HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053,…

  • CVE-2017-18640HigDec 12, 2019
    risk 0.51cvss 7.5epss 0.27

    The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

  • CVE-2019-19726HigDec 12, 2019
    risk 0.54cvss 7.8epss 0.04

    OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip…

  • CVE-2019-5154HigDec 12, 2019
    risk 0.57cvss 8.8epss 0.03

    An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A specially crafted J2K image file can cause an out of bounds write of a null byte in a heap buffer, potentially resulting in code execution. An attack can…

  • CVE-2019-5092HigDec 12, 2019
    risk 0.57cvss 8.8epss 0.02

    An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image format of LEADTOOLS 20.0.2019.3.15. A specially crafted DICOM image can cause an offset beyond the bounds of a heap allocation to be written, potentially resulting…

  • CVE-2019-5091HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an infinite loop, resulting in a denial of service. An attacker can send a packet to trigger this…

  • CVE-2019-5090HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.02

    An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an out-of-bounds read, resulting in information disclosure. An attacker can send a packet…

  • CVE-2019-3988HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.02

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.

  • CVE-2019-3987HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.02

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.

  • CVE-2019-3986HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.01

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter.

  • CVE-2019-3985HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.02

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.

  • CVE-2019-18245HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.00

    Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.

  • CVE-2019-18232HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.00

    SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using…

  • CVE-2019-17087HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system running AcuToWeb, with the privileges of the account AcuToWeb is running under.

  • CVE-2019-0405HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information Disclosure.

  • CVE-2019-0404HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.

  • CVE-2019-0398HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.

  • CVE-2019-19729HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects…

  • CVE-2019-19373HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_con…

  • CVE-2013-3691HigDec 11, 2019
    risk 0.52cvss 7.5epss 0.04

    AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.

  • CVE-2019-19650HigDec 11, 2019
    risk 0.58cvss 8.8epss 0.06

    Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.

  • CVE-2019-19583HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the…

  • CVE-2019-19578HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at…

  • CVE-2019-19577HigDec 11, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically…

  • CVE-2019-18379HigDec 11, 2019
    risk 0.48cvss 7.3epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through…

  • CVE-2019-18377HigDec 11, 2019
    risk 0.47cvss 7.2epss 0.01

    Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2014-0163HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.02

    Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

  • CVE-2019-4715HigDec 11, 2019
    risk 0.58cvss 8.8epss 0.04

    IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093.