VYPR

CVEs

101,972 total · page 1556 of 2,040

  • CVE-2019-14899HigDec 11, 2019
    risk 0.48cvss 7.4epss 0.01

    A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct…

  • CVE-2013-4593HigDec 11, 2019
    risk 0.42cvss 7.5epss 0.02

    RubyGem omniauth-facebook has an access token security vulnerability

  • CVE-2013-4245HigDec 11, 2019
    risk 0.47cvss 7.3epss 0.01

    Orca has arbitrary code execution due to insecure Python module load

  • CVE-2019-19720HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.01

    Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file.

  • CVE-2019-19707HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.

  • CVE-2019-5815HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.02

    Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.

  • CVE-2019-19604HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.04

    Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.

  • CVE-2019-14889HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.03

    A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way…

  • CVE-2019-1489HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.08

    An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'.

  • CVE-2019-1485HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.

  • CVE-2019-1484HigDec 10, 2019
    risk 0.51cvss 7.8epss 0.09

    A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.

  • CVE-2019-1483HigDec 10, 2019
    risk 0.51cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID…

  • CVE-2019-1478HigDec 10, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.

  • CVE-2019-1477HigDec 10, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'.

  • CVE-2019-1476HigDec 10, 2019
    risk 0.54cvss 7.8epss 0.05

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.

  • CVE-2019-1471HigDec 10, 2019
    risk 0.54cvss 8.2epss 0.08

    A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.

  • CVE-2019-1468HigDec 10, 2019
    risk 0.59cvss 8.8epss 0.17

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.

  • CVE-2019-1462HigDec 10, 2019
    risk 0.52cvss 7.8epss 0.18

    A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

  • CVE-2019-1458HigKEVDec 10, 2019
    risk 0.78cvss 7.8epss 0.74

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

  • CVE-2019-1453HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.09

    A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

  • CVE-2019-13764HigDec 10, 2019
    risk 0.58cvss 8.8epss 0.06

    Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13747HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13741HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

  • CVE-2019-13736HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-13735HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2019-13734HigDec 10, 2019
    risk 0.58cvss 8.8epss 0.04

    Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13732HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13730HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13729HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13728HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13727HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2019-13726HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2019-13725HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5843HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5841HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-19702HigDec 10, 2019
    risk 0.42cvss 7.5epss 0.01

    The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the…

  • CVE-2019-6183HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.02

    A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not…

  • CVE-2013-4133HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.03

    kde-workspace before 4.10.5 has a memory leak in plasma desktop

  • CVE-2013-4120HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.01

    Katello has a Denial of Service vulnerability in API OAuth authentication

  • CVE-2013-2183HigDec 10, 2019
    risk 0.46cvss 7.1epss 0.00

    Monkey HTTP Daemon has local security bypass

  • CVE-2013-1793HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.01

    openstack-utils openstack-db has insecure password creation

  • CVE-2013-0293HigDec 10, 2019
    risk 0.51cvss 7.8epss 0.00

    oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation

  • CVE-2019-4612HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.

  • CVE-2015-7892HigDec 9, 2019
    risk 0.54cvss 7.8epss 0.01

    Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.

  • CVE-2015-3424HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.

  • CVE-2014-0242HigDec 9, 2019
    risk 0.52cvss 7.5epss 0.09

    mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

  • CVE-2019-19603HigDec 9, 2019
    risk 0.01cvss 7.5epss 0.08

    SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.

  • CVE-2015-0841HigDec 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.

  • CVE-2019-19687HigDec 9, 2019
    risk 0.50cvss 8.8epss 0.02

    OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other…

  • CVE-2019-19685HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.01

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.