VYPR

CVEs

101,988 total · page 1771 of 2,040

  • CVE-2017-6294HigJun 7, 2018
    risk 0.51cvss 7.8epss 0.00

    In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to missing bounds check which could lead to escalation of privilege from the kernel to the TZ. User interaction is not needed for exploitation. This issue is…

  • CVE-2017-6292HigJun 7, 2018
    risk 0.51cvss 7.8epss 0.00

    In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which could lead to local escalation of privilege in the TrustZone with no additional execution privileges needed. User interaction is not…

  • CVE-2017-6290HigJun 7, 2018
    risk 0.51cvss 7.8epss 0.00

    In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which could lead to local escalation of privilege with no additional execution privileges needed. User interaction not needed for…

  • CVE-2018-6670HigJun 7, 2018
    risk 0.50cvss 7.6epss 0.01

    External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential information via a crafted HTTP request parameter.

  • CVE-2018-12036HigJun 7, 2018
    risk 0.51cvss 7.8epss 0.02

    OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.

  • CVE-2018-1547HigJun 7, 2018
    risk 0.52cvss 8.0epss 0.02

    IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to…

  • CVE-2018-12016HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.

  • CVE-2018-7689HigJun 7, 2018
    risk 0.00cvss 7.1epss 0.01

    Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.

  • CVE-2018-7688HigJun 7, 2018
    risk 0.00cvss 7.1epss 0.01

    A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.

  • CVE-2018-12015HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.07

    In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

  • CVE-2018-0353HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.04

    A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and bypass security protections. The vulnerability is due to a change in the…

  • CVE-2018-0322HigJun 7, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to a failure to…

  • CVE-2018-0317HigJun 7, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to escalate their privileges. The vulnerability is due to insufficient web portal access control checks. An attacker could exploit this…

  • CVE-2018-0316HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a…

  • CVE-2018-0296HigKEVJun 7, 2018
    risk 0.72cvss 7.5epss 1.00

    A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software…

  • CVE-2018-0274HigJun 7, 2018
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insufficient input validation. An attacker could…

  • CVE-2018-0263HigJun 7, 2018
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal…

  • CVE-2017-6779HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.…

  • CVE-2018-3737HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.

  • CVE-2018-3732HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3731HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3730HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3729HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3727HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3725HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3724HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3723HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3722HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3720HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3719HigJun 7, 2018
    risk 0.50cvss 8.8epss 0.02

    mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all…

  • CVE-2018-3711HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.

  • CVE-2017-16225HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.

  • CVE-2017-16223HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16221HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16220HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16219HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16218HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16217HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16216HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16215HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16214HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16213HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16212HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16211HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16210HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16209HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16208HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16207HigJun 7, 2018
    risk 0.48cvss 7.3epss 0.01

    discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.

  • CVE-2017-16206HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

  • CVE-2017-16205HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.