VYPR

CVEs

102,253 total · page 1695 of 2,046

  • CVE-2018-20547HigDec 28, 2018
    risk 0.53cvss 8.1epss 0.02

    There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.

  • CVE-2018-20546HigDec 28, 2018
    risk 0.00cvss 8.1epss 0.02

    There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.

  • CVE-2018-20545HigDec 28, 2018
    risk 0.00cvss 8.8epss 0.02

    There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

  • CVE-2018-20542HigDec 28, 2018
    risk 0.00cvss 8.8epss 0.02

    There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).

  • CVE-2018-20541HigDec 28, 2018
    risk 0.00cvss 8.8epss 0.02

    There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a different part of the source code and is seen at different addresses).

  • CVE-2018-17539HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.02

    The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attackers to cause a denial of service attack via an autonomous system (AS) path containing 8 or more autonomous system number (ASN) elements.

  • CVE-2018-1000890HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.02

    FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.

  • CVE-2018-1000889HigDec 28, 2018
    risk 0.57cvss 8.8epss 0.01

    Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration.…

  • CVE-2018-1000888HigDec 28, 2018
    risk 0.55cvss 8.8epss 0.19

    PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific…

  • CVE-2018-1000630HigDec 28, 2018
    risk 0.47cvss 7.2epss 0.02

    Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to /api/PluginStatusActions.php and /status/pluginStatus.php using the jtSorting or id parameter, which could allow the attacker to view, add,…

  • CVE-2018-1000624HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.02

    Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http://V2I_HUB/UI/powerdown.php, a remote attacker could exploit this vulnerability to shut down the system.

  • CVE-2018-20519HigDec 27, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter.

  • CVE-2018-20404HigDec 26, 2018
    risk 0.49cvss 7.5epss 0.01

    ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (uncontrollable) address, resulting in an eternal hang or a BSoD.

  • CVE-2018-19870HigDec 26, 2018
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.

  • CVE-2018-19616HigDec 26, 2018
    risk 0.58cvss 8.1epss 0.30

    An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.

  • CVE-2018-19182HigDec 26, 2018
    risk 0.00cvss 8.8epss 0.01

    Engelsystem before commit hash 2e28336 allows CSRF.

  • CVE-2018-18536HigDec 26, 2018
    risk 0.51cvss 7.8epss 0.01

    The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

  • CVE-2018-18535HigDec 26, 2018
    risk 0.51cvss 7.8epss 0.01

    The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.

  • CVE-2018-17987HigDec 26, 2018
    risk 0.49cvss 7.5epss 0.01

    The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an…

  • CVE-2018-15518HigDec 26, 2018
    risk 0.50cvss 8.8epss 0.03

    QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.

  • CVE-2018-20483HigDec 26, 2018
    risk 0.51cvss 7.8epss 0.01

    set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by…

  • CVE-2018-20478HigDec 26, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.

  • CVE-2018-20465HigDec 25, 2018
    risk 0.47cvss 7.2epss 0.02

    Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes…

  • CVE-2018-20463HigDec 25, 2018
    risk 0.50cvss 7.5epss 0.13

    An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

  • CVE-2018-20452HigDec 25, 2018
    risk 0.57cvss 8.8epss 0.02

    The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in…

  • CVE-2018-20437HigDec 25, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of…

  • CVE-2018-20436HigDec 24, 2018
    risk 0.53cvss 8.1epss 0.02

    The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also…

  • CVE-2018-20249HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.

  • CVE-2018-20247HigDec 24, 2018
    risk 0.55cvss 7.8epss 0.54

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.

  • CVE-2018-19232HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.01

    The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to cause a denial of service via a FIRMWAREUPDATE GET request, as demonstrated by the /DOWN/FIRMWAREUPDATE/ROM1 URI.

  • CVE-2018-18959HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then…

  • CVE-2018-7837HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.01

    An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect…

  • CVE-2018-7835HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.02

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow access to files available to SYSTEM user.

  • CVE-2018-7832HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.02

    An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched.

  • CVE-2018-7802HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.02

    A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.

  • CVE-2018-7801HigDec 24, 2018
    risk 0.58cvss 8.8epss 0.06

    A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote code execution is performed.

  • CVE-2018-7793HigDec 24, 2018
    risk 0.57cvss 8.7epss 0.00

    A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control Core Services 9.4 (CCS 9.4) and FoxView 10.5.) which could cause unauthorized disclosure, modification, or disruption in service…

  • CVE-2018-8920HigDec 24, 2018
    risk 0.47cvss 7.2epss 0.01

    Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.

  • CVE-2018-8919HigDec 24, 2018
    risk 0.54cvss 8.3epss 0.01

    Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.

  • CVE-2018-15465HigDec 24, 2018
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to…

  • CVE-2018-19357HigDec 24, 2018
    risk 0.51cvss 7.8epss 0.03

    XMPlay 3.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted http:// URL in a .m3u file.

  • CVE-2018-20429HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165.

  • CVE-2018-20428HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.

  • CVE-2018-20427HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.

  • CVE-2018-20426HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.

  • CVE-2018-20425HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.

  • CVE-2018-20423HigDec 24, 2018
    risk 0.53cvss 8.1epss 0.01

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.

  • CVE-2018-20422HigDec 24, 2018
    risk 0.53cvss 8.1epss 0.01

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which…

  • CVE-2018-20421HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.01

    Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstrated by use of "assembly { mstore }"…

  • CVE-2018-20419HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.00

    DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.