VYPR

CVEs

101,990 total · page 1763 of 2,040

  • CVE-2018-0595HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0594HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0593HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0592HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.05

    Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0584HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    IIJ SmartKey App for Android version 2.1.0 and earlier allows remote attackers to bypass authentication [effect_of_bypassing_authentication] via unspecified vectors.

  • CVE-2018-0572HigJun 26, 2018
    risk 0.53cvss 8.1epss 0.02

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors.

  • CVE-2018-0569HigJun 26, 2018
    risk 0.57cvss 8.8epss 0.01

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-0563HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.13.0 and earlier versions and FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.13.0 and earlier versions allows an attacker to gain privileges via a Trojan horse…

  • CVE-2018-12603HigJun 25, 2018
    risk 0.60cvss 8.8epss 0.04

    Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.

  • CVE-2018-12735HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inverter_info.htm or english_main.htm URI.

  • CVE-2018-12602HigJun 25, 2018
    risk 0.60cvss 8.8epss 0.03

    A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.

  • CVE-2018-11040HigJun 25, 2018
    risk 0.42cvss 7.5epss 0.03

    Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and…

  • CVE-2018-10956HigJun 25, 2018
    risk 0.56cvss 7.5epss 0.55

    IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.

  • CVE-2017-9312HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.04

    Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service. When a crafted TCP packet is received, the device reboots immediately.

  • CVE-2018-12084HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

  • CVE-2018-12083HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for GOAL Bonanza (GOAL), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

  • CVE-2018-12082HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for Fujinto (NTO), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

  • CVE-2018-12081HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

  • CVE-2018-12080HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap"…

  • CVE-2018-12079HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

  • CVE-2018-12078HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The mintToken function of a smart contract implementation for PolyAI (AI), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

  • CVE-2018-12070HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The sell function of a smart contract implementation for SEC, a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable…

  • CVE-2018-12068HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The sell function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable…

  • CVE-2018-12067HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable…

  • CVE-2018-12063HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a…

  • CVE-2018-12062HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable…

  • CVE-2018-11446HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The buy function of a smart contract implementation for Gold Reward (GRX), an Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the buyer because of overflow of the multiplication of its argument amount and a manipulable variable…

  • CVE-2018-12703HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The approveAndCallcode function of a smart contract implementation for Block 18 (18T), an tradable Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not…

  • CVE-2018-12702HigJun 25, 2018
    risk 0.49cvss 7.5epss 0.01

    The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is…

  • CVE-2018-12698HigJun 23, 2018
    risk 0.49cvss 7.5epss 0.07

    demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of…

  • CVE-2018-12697HigJun 23, 2018
    risk 0.49cvss 7.5epss 0.05

    A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.

  • CVE-2018-12694HigJun 23, 2018
    risk 0.49cvss 7.5epss 0.01

    TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json.

  • CVE-2018-12692HigJun 23, 2018
    risk 0.60cvss 8.8epss 0.29

    TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.

  • CVE-2018-12687HigJun 22, 2018
    risk 0.49cvss 7.5epss 0.01

    tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

  • CVE-2018-12684HigJun 22, 2018
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.

  • CVE-2018-12538HigJun 22, 2018
    risk 0.57cvss 8.8epss 0.03

    In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the…

  • CVE-2018-1000201HigJun 22, 2018
    risk 0.44cvss 7.8epss 0.01

    ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.

  • CVE-2018-12636HigJun 22, 2018
    risk 0.52cvss 7.2epss 0.30

    The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

  • CVE-2018-12659HigJun 22, 2018
    risk 0.57cvss 8.8epss 0.01

    SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.

  • CVE-2018-12648HigJun 22, 2018
    risk 0.49cvss 7.5epss 0.02

    The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.

  • CVE-2017-7466HigJun 22, 2018
    risk 0.45cvss 8.0epss 0.03

    Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute…

  • CVE-2018-12642HigJun 22, 2018
    risk 0.42cvss 7.5epss 0.01

    Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

  • CVE-2018-12635HigJun 22, 2018
    risk 0.49cvss 7.5epss 0.01

    CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.

  • CVE-2018-12631HigJun 21, 2018
    risk 0.49cvss 7.5epss 0.03

    Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/text?LFN=../ directory traversal.

  • CVE-2018-12613HigJun 21, 2018
    risk 0.61cvss 8.8epss 0.98

    An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for…

  • CVE-2018-7683HigJun 21, 2018
    risk 0.49cvss 7.5epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

  • CVE-2018-12617HigJun 21, 2018
    risk 0.54cvss 7.5epss 0.25

    qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be…

  • CVE-2018-0365HigJun 21, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to…

  • CVE-2018-0364HigJun 21, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is…

  • CVE-2018-0363HigJun 21, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected…