VYPR

CVEs

102,253 total · page 1683 of 2,046

  • CVE-2018-19029HigFeb 5, 2019
    risk 0.51cvss 7.8epss 0.03

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.

  • CVE-2018-19002HigFeb 5, 2019
    risk 0.51cvss 7.8epss 0.03

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash.

  • CVE-2018-18992HigFeb 5, 2019
    risk 0.57cvss 8.8epss 0.02

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.

  • CVE-2018-18986HigFeb 5, 2019
    risk 0.51cvss 7.8epss 0.03

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltration, or remote code execution.

  • CVE-2019-3818HigFeb 5, 2019
    risk 0.49cvss 7.5epss 0.01

    The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and…

  • CVE-2018-11803HigFeb 5, 2019
    risk 0.53cvss 7.5epss 0.58

    Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.

  • CVE-2018-15658HigFeb 5, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user. This is caused by the session validation occurring after the…

  • CVE-2018-15657HigFeb 5, 2019
    risk 0.51cvss 7.3epss 0.02

    An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.

  • CVE-2018-15656HigFeb 5, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email, where :email is a base64 encoded e-mail address, to receive confirmation as to whether a user account exists in the system…

  • CVE-2019-7398HigFeb 5, 2019
    risk 0.42cvss 7.5epss 0.04

    In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.

  • CVE-2019-7397HigFeb 5, 2019
    risk 0.42cvss 7.5epss 0.04

    In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.

  • CVE-2019-7396HigFeb 5, 2019
    risk 0.42cvss 7.5epss 0.03

    In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.

  • CVE-2019-7395HigFeb 5, 2019
    risk 0.42cvss 7.5epss 0.03

    In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.

  • CVE-2019-7390HigFeb 5, 2019
    risk 0.56cvss 8.6epss 0.02

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.

  • CVE-2019-7389HigFeb 5, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefault HNAP API. Consequently, an attacker can achieve a…

  • CVE-2019-7388HigFeb 5, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an…

  • CVE-2018-15778HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.00

    Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-line interface (CLI).

  • CVE-2019-1000022HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.01

    Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against…

  • CVE-2019-1000021HigFeb 4, 2019
    risk 0.42cvss 7.5epss 0.02

    slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage of Private Data via PubSub) options profile, used for the configuration of default access model that can result in all…

  • CVE-2019-1000018HigFeb 4, 2019
    risk 0.51cvss 7.8epss 0.02

    rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the…

  • CVE-2019-1000014HigFeb 4, 2019
    risk 0.00cvss 8.8epss 0.02

    Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via Victim fetches packages from…

  • CVE-2019-1000013HigFeb 4, 2019
    risk 0.00cvss 8.8epss 0.01

    Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from…

  • CVE-2019-1000012HigFeb 4, 2019
    risk 0.00cvss 8.8epss 0.01

    Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from…

  • CVE-2019-1000007HigFeb 4, 2019
    risk 0.41cvss 7.4epss 0.01

    aioxmpp version 0.10.2 and earlier contains a Improper Handling of Structural Elements vulnerability in Stanza Parser, rollback during error processing, aioxmpp.xso.model.guard function that can result in Denial of Service, Other. This attack appears to be exploitable via…

  • CVE-2019-1000005HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.02

    mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted…

  • CVE-2019-1000003HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.01

    MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via…

  • CVE-2018-1970HigFeb 4, 2019
    risk 0.46cvss 7.1epss 0.02

    IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.

  • CVE-2019-7350HigFeb 4, 2019
    risk 0.48cvss 7.3epss 0.01

    Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking the victim's account. This occurs because a set of multiple cookies (between 3 and 5) is being generated when a user successfully…

  • CVE-2019-7347HigFeb 4, 2019
    risk 0.49cvss 7.5epss 0.01

    A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.).

  • CVE-2019-7346HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

  • CVE-2018-20751HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this…

  • CVE-2019-3813HigFeb 4, 2019
    risk 0.49cvss 7.5epss 0.01

    Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

  • CVE-2019-3461HigFeb 4, 2019
    risk 0.46cvss 7.0epss 0.00

    Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the…

  • CVE-2019-7323HigFeb 4, 2019
    risk 0.49cvss 7.5epss 0.01

    GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update process relies on cleartext HTTP. The attacker could…

  • CVE-2019-7310HigFeb 3, 2019
    risk 0.51cvss 7.8epss 0.02

    In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as…

  • CVE-2018-16493HigFeb 1, 2019
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.

  • CVE-2018-16490HigFeb 1, 2019
    risk 0.49cvss 7.5epss 0.01

    A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

  • CVE-2018-16483HigFeb 1, 2019
    risk 0.57cvss 8.8epss 0.01

    A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

  • CVE-2018-16482HigFeb 1, 2019
    risk 0.49cvss 7.5epss 0.02

    A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.

  • CVE-2018-16479HigFeb 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL.

  • CVE-2018-0722HigFeb 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.

  • CVE-2018-18988HigFeb 1, 2019
    risk 0.57cvss 8.8epss 0.03

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash.

  • CVE-2019-7301HigFeb 1, 2019
    risk 0.47cvss 7.2epss 0.03

    Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter.

  • CVE-2019-7300HigFeb 1, 2019
    risk 0.47cvss 7.2epss 0.03

    Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line field.

  • CVE-2017-18361HigFeb 1, 2019
    risk 0.42cvss 7.5epss 0.02

    In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.

  • CVE-2019-7298HigFeb 1, 2019
    risk 0.53cvss 8.1epss 0.10

    An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. This occurs when any HNAP API function triggers a call to the system function with…

  • CVE-2018-6241HigJan 31, 2019
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High…

  • CVE-2018-15517HigJan 31, 2019
    risk 0.59cvss 8.6epss 0.44

    The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/…

  • CVE-2018-15515HigJan 31, 2019
    risk 0.51cvss 7.8epss 0.02

    The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.

  • CVE-2019-7283HigJan 31, 2019
    risk 0.48cvss 7.4epss 0.02

    An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle…