VYPR

CVEs

101,988 total · page 1780 of 2,040

  • CVE-2016-10529HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.00

    Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new…

  • CVE-2016-10527HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.02

    The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.

  • CVE-2016-10526HigMay 31, 2018
    risk 0.49cvss 8.6epss 0.02

    A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this…

  • CVE-2016-10524HigMay 31, 2018
    risk 0.46cvss 8.2epss 0.01

    i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for development in i18n-node-angular before 1.4.0 was not disabled in production environments a malicious user could fill up the server…

  • CVE-2016-10523HigMay 31, 2018
    risk 0.42cvss 7.5epss 0.02

    MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very little bandwidth.

  • CVE-2016-10521HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.

  • CVE-2016-10520HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

  • CVE-2016-10519HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.02

    A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to reveal internal memory.

  • CVE-2016-10518HigMay 31, 2018
    risk 0.42cvss 7.5epss 0.02

    A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memory by sending a ping frame. The ping functionality by default responds with a pong frame and the previously given payload of the ping frame. This is exactly…

  • CVE-2015-9239HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

  • CVE-2014-10066HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.02

    Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.

  • CVE-2014-10064HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service…

  • CVE-2018-11626HigMay 31, 2018
    risk 0.49cvss 7.5epss 0.01

    SELA (aka SimplE Lossless Audio) v0.1.2-alpha has a stack-based buffer overflow in the core/apev2.c init_apev2_keys function.

  • CVE-2018-11139HigMay 31, 2018
    risk 0.61cvss 8.8epss 0.43

    The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized…

  • CVE-2018-11135HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.02

    The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks.

  • CVE-2018-11134HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.03

    In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password…

  • CVE-2018-11132HigMay 31, 2018
    risk 0.59cvss 8.8epss 0.18

    In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within…

  • CVE-2018-11625HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.02

    In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

  • CVE-2018-11624HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.02

    In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a crafted file.

  • CVE-2018-11598HigMay 31, 2018
    risk 0.00cvss 7.1epss 0.01

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jsparse.c.

  • CVE-2018-11595HigMay 31, 2018
    risk 0.00cvss 7.8epss 0.01

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow during syntax parsing, because strncat is misused.

  • CVE-2018-11593HigMay 31, 2018
    risk 0.00cvss 7.1epss 0.01

    Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow during syntax parsing because strncpy is misused in jslex.c.

  • CVE-2018-11220HigMay 31, 2018
    risk 0.62cvss 8.8epss 0.16

    Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.

  • CVE-2018-9322HigMay 31, 2018
    risk 0.51cvss 7.8epss 0.01

    The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows local attacks involving the USB or OBD-II interface. An attacker can bypass the code-signing protection…

  • CVE-2018-9320HigMay 31, 2018
    risk 0.51cvss 7.8epss 0.01

    The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in.

  • CVE-2018-9312HigMay 31, 2018
    risk 0.51cvss 7.8epss 0.01

    The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in.

  • CVE-2018-11577HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.03

    Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.

  • CVE-2018-11571HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.01

    ClipperCMS 1.3.3 allows Session Fixation.

  • CVE-2018-11481HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.02

    TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.

  • CVE-2018-11478HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line /…

  • CVE-2018-11476HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to connect to the network without authentication.

  • CVE-2015-7610HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging…

  • CVE-2018-11518HigMay 30, 2018
    risk 0.53cvss 8.1epss 0.01

    A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone…

  • CVE-2018-11438HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.03

    The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.

  • CVE-2018-11556HigMay 30, 2018
    risk 0.51cvss 7.8epss 0.01

    tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and…

  • CVE-2018-11555HigMay 30, 2018
    risk 0.51cvss 7.8epss 0.01

    tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply…

  • CVE-2018-11235HigMay 30, 2018
    risk 0.55cvss 7.8epss 0.49

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone…

  • CVE-2018-11233HigMay 30, 2018
    risk 0.49cvss 7.5epss 0.05

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

  • CVE-2018-11548HigMay 29, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP address.

  • CVE-2018-6964HigMay 29, 2018
    risk 0.51cvss 7.8epss 0.00

    VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where…

  • CVE-2018-3734HigMay 29, 2018
    risk 0.49cvss 7.5epss 0.02

    stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.

  • CVE-2018-3733HigMay 29, 2018
    risk 0.42cvss 7.5epss 0.02

    crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.

  • CVE-2018-11392HigMay 29, 2018
    risk 0.58cvss 8.8epss 0.05

    An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile avatar field. This results…

  • CVE-2017-16153HigMay 29, 2018
    risk 0.49cvss 7.5epss 0.02

    gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2017-16062HigMay 29, 2018
    risk 0.49cvss 7.5epss 0.01

    node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16061HigMay 29, 2018
    risk 0.49cvss 7.5epss 0.01

    tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16047HigMay 29, 2018
    risk 0.49cvss 7.5epss 0.01

    mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

  • CVE-2017-16003HigMay 29, 2018
    risk 0.46cvss 8.1epss 0.02

    windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below 1.0.0 download resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the…

  • CVE-2016-10698HigMay 29, 2018
    risk 0.53cvss 8.1epss 0.02

    mystem-fix is a node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem-fix downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an…

  • CVE-2016-10682HigMay 29, 2018
    risk 0.53cvss 8.1epss 0.02

    massif is a Phantomjs fork massif downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or…