VYPR

CVEs

101,988 total · page 1774 of 2,040

  • CVE-2017-16093HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16092HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

  • CVE-2017-16091HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

  • CVE-2017-16090HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16089HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

  • CVE-2017-16086HigJun 7, 2018
    risk 0.52cvss 7.5epss 0.09

    ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.

  • CVE-2017-16085HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

  • CVE-2017-16084HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16083HigJun 7, 2018
    risk 0.42cvss 7.5epss 0.02

    node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

  • CVE-2017-16081HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16080HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16079HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16078HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16077HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16076HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16075HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16074HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16073HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16072HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16071HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16070HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16069HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16068HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16067HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16066HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16065HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16064HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16063HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16060HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16059HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16058HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16057HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16056HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.01

    mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2018-5850HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-5846HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD…

  • CVE-2018-5845HigJun 6, 2018
    risk 0.46cvss 7.0epss 0.00

    A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-5841HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-5840HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-3852HigJun 6, 2018
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet can cause a process to terminate resulting in denial of service. An attacker can send a crafted TCP packet to trigger this…

  • CVE-2018-3580HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-3578HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading to a heap buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-3565HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overflow can occur.

  • CVE-2017-18154HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

  • CVE-2018-1265HigJun 6, 2018
    risk 0.47cvss 7.2epss 0.02

    Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps…

  • CVE-2017-7906HigJun 6, 2018
    risk 0.57cvss 8.8epss 0.01

    In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.

  • CVE-2018-1000203HigJun 6, 2018
    risk 0.49cvss 7.5epss 0.01

    Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zero_fee_transaction() that can result in theft of Soar Coins by the…

  • CVE-2018-1456HigJun 6, 2018
    risk 0.46cvss 7.1epss 0.02

    IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.

  • CVE-2018-11813HigJun 6, 2018
    risk 0.49cvss 7.5epss 0.03

    libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

  • CVE-2018-7884HigJun 5, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version: cl_1956.exe is run as SYSTEM on the %systemroot%\Temp folder, where any user…

  • CVE-2018-10058HigJun 5, 2018
    risk 0.58cvss 8.8epss 0.04

    The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.