VYPR

CVEs

102,253 total · page 1690 of 2,046

  • CVE-2019-6250HigJan 13, 2019
    risk 0.58cvss 8.8epss 0.09

    A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of bytes beyond the bounds of a…

  • CVE-2019-6249HigJan 13, 2019
    risk 0.60cvss 8.8epss 0.03

    An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.

  • CVE-2019-6247HigJan 13, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the render_scanlines_aa_solid function, the blend_hline function is called repeatedly multiple times.…

  • CVE-2019-6245HigJan 13, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be…

  • CVE-2019-6244HigJan 12, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file.

  • CVE-2018-16865HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.03

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw…

  • CVE-2018-16864HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.01

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate…

  • CVE-2018-4404HigJan 11, 2019
    risk 0.61cvss 8.8epss 0.14

    In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.

  • CVE-2018-4330HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.03

    In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.

  • CVE-2018-4277HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.02

    In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.

  • CVE-2018-4262HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.03

    In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.

  • CVE-2018-4217HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

  • CVE-2018-4213HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

  • CVE-2018-4212HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

  • CVE-2018-4210HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.

  • CVE-2018-4209HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

  • CVE-2018-4208HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

  • CVE-2018-4207HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

  • CVE-2018-4194HigJan 11, 2019
    risk 0.57cvss 8.8epss 0.02

    In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

  • CVE-2018-4186HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation.

  • CVE-2018-4185HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.03

    In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.

  • CVE-2018-4183HigJan 11, 2019
    risk 0.46cvss 8.2epss 0.00

    In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.

  • CVE-2018-4182HigJan 11, 2019
    risk 0.53cvss 8.2epss 0.00

    In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions on CUPS.

  • CVE-2018-4180HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

  • CVE-2017-13888HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In iOS before 11.2, a type confusion issue was addressed with improved memory handling.

  • CVE-2017-13887HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.

  • CVE-2016-7576HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.01

    In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.

  • CVE-2019-6138HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory leaks when called from mms/iso_mms/common/mms_value.c, server/mms_mapping/mms_mapping.c, and server/mms_mapping/mms_sv.c (via common/string_utilities.c), as…

  • CVE-2019-6137HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in lib60870 2.1.1. LinkLayer_setAddress in link_layer/link_layer.c has a NULL pointer dereference.

  • CVE-2019-6136HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a SEGV, as demonstrated by sv_subscriber_example.c and sv_subscriber.c.

  • CVE-2019-6135HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called from Asn1PrimitiveValue_create in mms/asn1/asn1_ber_primitive_value.c, as demonstrated by goose_publisher_example.c and iec61850_9_2_LE_example.c.

  • CVE-2019-6132HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp when called from the AP4_EsdsAtom class in Core/Ap4EsdsAtom.cpp, as demonstrated by mp42aac.

  • CVE-2019-6128HigJan 11, 2019
    risk 0.58cvss 8.8epss 0.04

    The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

  • CVE-2019-6127HigJan 11, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.

  • CVE-2019-6126HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.php, as demonstrated by disclosure of information about users and staff.

  • CVE-2018-5413HigJan 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.

  • CVE-2018-5412HigJan 10, 2019
    risk 0.51cvss 7.8epss 0.01

    Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.

  • CVE-2018-5403HigJan 10, 2019
    risk 0.53cvss 8.1epss 0.02

    Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.

  • CVE-2018-15460HigJan 10, 2019
    risk 0.56cvss 8.6epss 0.03

    A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an…

  • CVE-2018-20684HigJan 10, 2019
    risk 0.00cvss 7.5epss 0.03

    In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.

  • CVE-2019-0088HigJan 10, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient path checking in Intel(R) System Support Utility for Windows before 2.5.0.15 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2018-3703HigJan 10, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper directory permissions in the installer for the Intel(R) SSD Data Center Tool for Windows before v3.0.17 may allow authenticated users to potentially enable an escalation of privilege via local access.

  • CVE-2018-18098HigJan 10, 2019
    risk 0.47cvss 7.3epss 0.00

    Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.

  • CVE-2018-12177HigJan 10, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.0.7 may allow an authorized user to potentially enable escalation of privilege via local access.

  • CVE-2018-15453HigJan 10, 2019
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause an…

  • CVE-2018-0474HigJan 10, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in configuration pages. An…

  • CVE-2019-5887HigJan 10, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input mishandling by the rmdir method. Attackers can delete arbitrary files by using "../" directory traversal.

  • CVE-2018-20683HigJan 10, 2019
    risk 0.00cvss 8.1epss 0.02

    commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P.

  • CVE-2018-0181HigJan 10, 2019
    risk 0.48cvss 7.3epss 0.02

    A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis server. The…

  • CVE-2018-16202HigJan 9, 2019
    risk 0.56cvss 8.6epss 0.03

    Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.