VYPR

CVEs

101,988 total · page 1775 of 2,040

  • CVE-2018-1000197HigJun 5, 2018
    risk 0.53cvss 8.1epss 0.01

    An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.

  • CVE-2018-1000194HigJun 5, 2018
    risk 0.46cvss 8.1epss 0.03

    A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.

  • CVE-2017-7635HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.01

    QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.

  • CVE-2018-10601HigJun 5, 2018
    risk 0.53cvss 8.2epss 0.00

    IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have…

  • CVE-2018-10597HigJun 5, 2018
    risk 0.54cvss 8.3epss 0.00

    IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have…

  • CVE-2018-1000189HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.02

    A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.

  • CVE-2017-7654HigJun 5, 2018
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.

  • CVE-2018-7943HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.01

    There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information…

  • CVE-2018-10966HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.02

    An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the…

  • CVE-2018-10813HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.01

    In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of…

  • CVE-2017-1350HigJun 5, 2018
    risk 0.55cvss 8.4epss 0.00

    IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.

  • CVE-2018-6662HigJun 5, 2018
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a crafted user input.

  • CVE-2018-1000181HigJun 5, 2018
    risk 0.00cvss 7.5epss 0.01

    Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in information disclosure.

  • CVE-2018-1000180HigJun 5, 2018
    risk 0.42cvss 7.5epss 0.04

    Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in…

  • CVE-2018-1252HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.02

    RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end…

  • CVE-2018-11740HigJun 5, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to disclose information or…

  • CVE-2018-11739HigJun 5, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function raw_read in tsk/img/raw.c which could be leveraged by an attacker to disclose information or manipulated to read…

  • CVE-2018-11738HigJun 5, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_make_data_run in tsk/fs/ntfs.c which could be leveraged by an attacker to disclose information or…

  • CVE-2018-11737HigJun 5, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_fix_idxrec in tsk/fs/ntfs_dent.cpp which could be leveraged by an attacker to disclose information or…

  • CVE-2016-1000352HigJun 4, 2018
    risk 0.41cvss 7.4epss 0.02

    In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

  • CVE-2016-1000344HigJun 4, 2018
    risk 0.41cvss 7.4epss 0.02

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

  • CVE-2018-3853HigJun 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can trigger a previously freed object in memory to be reused resulting in arbitrary code execution. An attacker…

  • CVE-2017-16055HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16054HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16053HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16052HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16051HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16050HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16049HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16048HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16046HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16045HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16044HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    `d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16040HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if…

  • CVE-2017-16039HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.02

    `hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16038HigJun 4, 2018
    risk 0.00cvss 7.5epss 0.03

    `f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. This is compounded by `f2e-server` requiring elevated privileges to run.

  • CVE-2017-16037HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.02

    `gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.

  • CVE-2017-16036HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.02

    `badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16035HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.01

    The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP…

  • CVE-2017-16031HigJun 4, 2018
    risk 0.42cvss 7.5epss 0.02

    Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io…

  • CVE-2017-16030HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.

  • CVE-2017-16029HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.02

    hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulnerability in hostr 2.3.5 and earlier that allows an attacker to read files outside the current directory by sending `../` in the url path for GET requests.

  • CVE-2017-16023HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.

  • CVE-2017-16014HigJun 4, 2018
    risk 0.00cvss 7.5epss 0.02

    Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.

  • CVE-2017-16013HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.02

    hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached.

  • CVE-2017-16005HigJun 4, 2018
    risk 0.49cvss 7.5epss 0.01

    Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he…

  • CVE-2016-8390HigJun 4, 2018
    risk 0.51cvss 7.8epss 0.01

    An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.11.20. A specially crafted ELF file can cause attacker controlled pointer arithmetic resulting in a partially controlled out of bounds write. An attacker can…

  • CVE-2016-10697HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the…

  • CVE-2016-10696HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested…

  • CVE-2016-10695HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested…