VYPR

CVEs

101,990 total · page 1764 of 2,040

  • CVE-2018-0358HigJun 21, 2018
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to exhaustion of file descriptors while…

  • CVE-2018-0337HigJun 21, 2018
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the affected software lacks proper input and validation checks…

  • CVE-2018-0313HigJun 21, 2018
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit. The vulnerability is due to incorrect input…

  • CVE-2018-0311HigJun 21, 2018
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software…

  • CVE-2018-0309HigJun 21, 2018
    risk 0.50cvss 7.7epss 0.02

    A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust…

  • CVE-2018-0306HigJun 21, 2018
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this…

  • CVE-2018-0305HigJun 21, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability exists because the affected software…

  • CVE-2018-0303HigJun 21, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. The vulnerability…

  • CVE-2018-0302HigJun 21, 2018
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem.…

  • CVE-2018-0300HigJun 21, 2018
    risk 0.47cvss 7.2epss 0.07

    A vulnerability in the process of uploading new application images to Cisco FXOS on the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker using path traversal techniques to create or…

  • CVE-2018-0298HigJun 21, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An attacker could…

  • CVE-2018-0330HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerability is due to a failure to properly…

  • CVE-2018-0307HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this…

  • CVE-2018-0295HigJun 20, 2018
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the device unexpectedly reloading. The vulnerability is due to incomplete input…

  • CVE-2018-0293HigJun 20, 2018
    risk 0.58cvss 8.8epss 0.05

    A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should be restricted for a nonadministrative user. The attacker would have to possess valid user credentials for the device.…

  • CVE-2018-0292HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to…

  • CVE-2018-12604HigJun 20, 2018
    risk 0.53cvss 7.5epss 0.13

    GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

  • CVE-2018-5428HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.03

    The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data Virtualization: 7.0.5; 7.0.6.

  • CVE-2018-12600HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.03

    In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.

  • CVE-2018-12599HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.03

    In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.

  • CVE-2018-10841HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.01

    glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to…

  • CVE-2018-6211HigJun 20, 2018
    risk 0.47cvss 7.2epss 0.06

    On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.

  • CVE-2018-5237HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.02

    Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.

  • CVE-2018-6563HigJun 20, 2018
    risk 0.60cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by…

  • CVE-2018-12558HigJun 20, 2018
    risk 0.49cvss 7.5epss 0.03

    The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

  • CVE-2018-12594HigJun 20, 2018
    risk 0.49cvss 7.5epss 0.01

    Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml or job/job.json file, as demonstrated the Master Password field.

  • CVE-2018-1132HigJun 20, 2018
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series…

  • CVE-2018-12592HigJun 20, 2018
    risk 0.49cvss 7.5epss 0.01

    Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chosen to turn off the video using a specific option). During those seconds, a meeting invitee may unknowingly be on camera with other…

  • CVE-2018-12591HigJun 20, 2018
    risk 0.47cvss 7.2epss 0.02

    Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrators themselves are allowed. An attacker with…

  • CVE-2018-12590HigJun 20, 2018
    risk 0.47cvss 7.2epss 0.02

    Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrators themselves are allowed. An attacker…

  • CVE-2018-8030HigJun 20, 2018
    risk 0.42cvss 7.5epss 0.04

    A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP…

  • CVE-2018-11707HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Read and Execute AV at 0x0057898e, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-11706HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578dd8, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-11705HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cc4, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-11704HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d7d, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-11703HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d6a, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-11702HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cb3, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-11701HigJun 20, 2018
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

  • CVE-2018-12519HigJun 19, 2018
    risk 0.61cvss 8.8epss 0.08

    An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.

  • CVE-2018-12294HigJun 19, 2018
    risk 0.57cvss 8.8epss 0.02

    WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use after free for a WebCore::TextureMapperLayer object.

  • CVE-2018-12293HigJun 19, 2018
    risk 0.61cvss 8.8epss 0.11

    The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer…

  • CVE-2018-11726HigJun 19, 2018
    risk 0.57cvss 8.8epss 0.03

    The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

  • CVE-2018-11724HigJun 19, 2018
    risk 0.57cvss 8.8epss 0.02

    The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

  • CVE-2018-11116HigJun 19, 2018
    risk 0.57cvss 8.8epss 0.02

    OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the…

  • CVE-2018-10945HigJun 19, 2018
    risk 0.49cvss 7.5epss 0.01

    The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.

  • CVE-2018-10811HigJun 19, 2018
    risk 0.49cvss 7.5epss 0.06

    strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

  • CVE-2018-8727HigJun 19, 2018
    risk 0.49cvss 7.5epss 0.08

    Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system to access files or directories via the Web Client webserver.

  • CVE-2018-11526HigJun 19, 2018
    risk 0.54cvss 7.8epss 0.05

    The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

  • CVE-2018-11525HigJun 19, 2018
    risk 0.47cvss 7.8epss 0.05

    The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

  • CVE-2018-12582HigJun 19, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI.