VYPR

CVEs

102,253 total · page 1694 of 2,046

  • CVE-2018-15490HigJan 2, 2019
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over…

  • CVE-2019-3574HigJan 2, 2019
    risk 0.51cvss 7.8epss 0.01

    In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.

  • CVE-2018-20658HigJan 2, 2019
    risk 0.52cvss 7.5epss 0.08

    The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.

  • CVE-2018-5197HigJan 2, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters…

  • CVE-2018-20657HigJan 2, 2019
    risk 0.49cvss 7.5epss 0.04

    The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.

  • CVE-2018-17188HigJan 2, 2019
    risk 0.47cvss 7.2epss 0.03

    Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the underlying operating system as the CouchDB user. Together with other…

  • CVE-2019-3500HigJan 2, 2019
    risk 0.51cvss 7.8epss 0.00

    aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.

  • CVE-2019-3494HigJan 1, 2019
    risk 0.49cvss 7.5epss 0.01

    Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.

  • CVE-2018-6347HigDec 31, 2018
    risk 0.00cvss 7.5epss 0.01

    An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.

  • CVE-2018-6346HigDec 31, 2018
    risk 0.00cvss 7.5epss 0.01

    A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.

  • CVE-2018-6344HigDec 31, 2018
    risk 0.49cvss 7.5epss 0.02

    A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for…

  • CVE-2018-6343HigDec 31, 2018
    risk 0.00cvss 7.5epss 0.01

    Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from…

  • CVE-2018-6340HigDec 31, 2018
    risk 0.00cvss 8.1epss 0.01

    The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

  • CVE-2018-6337HigDec 31, 2018
    risk 0.00cvss 7.5epss 0.02

    folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and…

  • CVE-2018-6336HigDec 31, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the…

  • CVE-2018-6335HigDec 31, 2018
    risk 0.00cvss 7.5epss 0.01

    A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.

  • CVE-2018-18601HigDec 31, 2018
    risk 0.53cvss 8.1epss 0.01

    The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.

  • CVE-2018-18600HigDec 31, 2018
    risk 0.53cvss 8.1epss 0.02

    The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

  • CVE-2018-20618HigDec 31, 2018
    risk 0.57cvss 8.8epss 0.01

    ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.

  • CVE-2018-20617HigDec 31, 2018
    risk 0.57cvss 8.8epss 0.01

    ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c.

  • CVE-2018-20616HigDec 31, 2018
    risk 0.57cvss 8.8epss 0.01

    ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c.

  • CVE-2018-20614HigDec 30, 2018
    risk 0.49cvss 7.5epss 0.01

    public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.

  • CVE-2018-20613HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.00

    TEMMOKU T1.09 Beta allows admin/user/add CSRF.

  • CVE-2018-20612HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.00

    UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

  • CVE-2018-20608HigDec 30, 2018
    risk 0.50cvss 7.5epss 0.12

    imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.

  • CVE-2018-20606HigDec 30, 2018
    risk 0.49cvss 7.5epss 0.03

    imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.

  • CVE-2018-20603HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.01

    Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.

  • CVE-2018-20602HigDec 30, 2018
    risk 0.49cvss 7.5epss 0.01

    Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.

  • CVE-2018-20599HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.02

    UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.

  • CVE-2018-20598HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.01

    UCMS 1.4.7 has ?do=user_addpost CSRF.

  • CVE-2018-20595HigDec 30, 2018
    risk 0.50cvss 8.8epss 0.01

    A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.

  • CVE-2018-15007HigDec 28, 2018
    risk 0.51cvss 7.8epss 0.00

    The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package name of com.fw.upgrade.sysoper (versionCode=238, versionName=2.3.8) that contains…

  • CVE-2018-15005HigDec 28, 2018
    risk 0.46cvss 7.1epss 0.00

    The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.zte.zdm.sdm (versionCode=31, versionName=V5.0.3) that contains an exported broadcast…

  • CVE-2018-14988HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that contains an exported broadcast receiver…

  • CVE-2018-14987HigDec 28, 2018
    risk 0.46cvss 7.1epss 0.00

    The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that dynamically registers a broadcast receiver app…

  • CVE-2018-14986HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0))…

  • CVE-2018-14985HigDec 28, 2018
    risk 0.46cvss 7.1epss 0.00

    The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-android.20170630.092853) that…

  • CVE-2018-14984HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0))…

  • CVE-2018-20579HigDec 28, 2018
    risk 0.46cvss 7.1epss 0.00

    Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-bounds write of an '{' or '[' character.

  • CVE-2018-20578HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in NuttX before 7.27. The function netlib_parsehttpurl() in apps/netutils/netlib/netlib_parsehttpurl.c mishandles URLs longer than hostlen bytes (in the webclient, this is set by default to 40), leading to an Infinite Loop. The attack vector is the…

  • CVE-2018-20575HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.

  • CVE-2018-18696HigDec 28, 2018
    risk 0.57cvss 8.8epss 0.01

    main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang…

  • CVE-2018-18667HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812.

  • CVE-2018-18666HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of SwftCoin (SWFTC) aka SwftCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

  • CVE-2018-18665HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

  • CVE-2018-20571HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.

  • CVE-2018-20553HigDec 28, 2018
    risk 0.00cvss 7.8epss 0.01

    Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.

  • CVE-2018-20552HigDec 28, 2018
    risk 0.00cvss 7.8epss 0.01

    Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c.

  • CVE-2018-20549HigDec 28, 2018
    risk 0.57cvss 8.8epss 0.02

    There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.

  • CVE-2018-20548HigDec 28, 2018
    risk 0.57cvss 8.8epss 0.02

    There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.