VYPR

CVEs

101,988 total · page 1789 of 2,040

  • CVE-2018-10749HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'commit <node_name>' function and cause memory corruption. Furthermore, it…

  • CVE-2018-10748HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'show <node_name>' function and cause memory corruption. Furthermore, it is…

  • CVE-2018-10747HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'unset <node_name>' function and cause memory corruption. Furthermore, it…

  • CVE-2018-10746HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'get <node_name attr>' function and cause memory corruption. Furthermore, it…

  • CVE-2018-9063HigMay 4, 2018
    risk 0.51cvss 7.8epss 0.00

    MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability where an attacker entering very large user ID or password can overrun the program's buffer, causing undefined behaviors, such as…

  • CVE-2018-8872HigMay 4, 2018
    risk 0.53cvss 8.1epss 0.02

    In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

  • CVE-2018-8861HigMay 4, 2018
    risk 0.57cvss 8.7epss 0.00

    Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) could enable a limited-access kiosk user or…

  • CVE-2018-8857HigMay 4, 2018
    risk 0.51cvss 7.8epss 0.00

    Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) contains fixed credentials, such as a password or cryptographic key, which it…

  • CVE-2018-8853HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.00

    Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating system. Windows boots by default with elevated Windows privileges, enabling a kiosk application, user, or an attacker to potentially attain unauthorized elevated…

  • CVE-2018-10641HigMay 4, 2018
    risk 0.53cvss 8.1epss 0.02

    D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.

  • CVE-2018-10722HigMay 4, 2018
    risk 0.51cvss 7.8epss 0.01

    In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify access to the %PROGRAMFILES%\Cylance\Desktop\log folder, the CyUpdate process grants users Modify access to new files created in this folder, and a new file…

  • CVE-2018-10168HigMay 3, 2018
    risk 0.57cvss 8.8epss 0.02

    TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.

  • CVE-2018-10167HigMay 3, 2018
    risk 0.49cvss 7.5epss 0.01

    The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify…

  • CVE-2018-10166HigMay 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled…

  • CVE-2018-10717HigMay 3, 2018
    risk 0.00cvss 8.8epss 0.02

    The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other…

  • CVE-2018-10713HigMay 3, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'read <node_name>' function and cause memory corruption. Furthermore, it is…

  • CVE-2018-4849HigMay 3, 2018
    risk 0.48cvss 7.4epss 0.01

    A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improper certificate validation could allow an attacker in a privileged network position to read data from…

  • CVE-2018-10666HigMay 3, 2018
    risk 0.49cvss 7.5epss 0.01

    The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables.

  • CVE-2018-0287HigMay 2, 2018
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to a design flaw in the affected software. An attacker…

  • CVE-2018-0262HigMay 2, 2018
    risk 0.53cvss 8.1epss 0.04

    A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of…

  • CVE-2018-0252HigMay 2, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service…

  • CVE-2018-0235HigMay 2, 2018
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is…

  • CVE-2018-0234HigMay 2, 2018
    risk 0.56cvss 8.6epss 0.04

    A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access Points could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service…

  • CVE-2018-0226HigMay 2, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated…

  • CVE-2018-10577HigMay 2, 2018
    risk 0.61cvss 8.8epss 0.07

    An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root,…

  • CVE-2018-10115HigMay 2, 2018
    risk 0.51cvss 7.8epss 0.05

    Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

  • CVE-2018-8115HigMay 2, 2018
    risk 0.59cvss 8.6epss 0.34

    A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host…

  • CVE-2018-1104HigMay 2, 2018
    risk 0.57cvss 8.8epss 0.03

    Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

  • CVE-2018-10677HigMay 2, 2018
    risk 0.00cvss 8.8epss 0.02

    The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a…

  • CVE-2018-1101HigMay 2, 2018
    risk 0.47cvss 7.2epss 0.02

    Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing…

  • CVE-2018-10675HigMay 2, 2018
    risk 0.00cvss 7.8epss 0.00

    The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.

  • CVE-2018-10657HigMay 2, 2018
    risk 0.42cvss 7.5epss 0.02

    Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

  • CVE-2013-6272HigMay 2, 2018
    risk 0.51cvss 7.8epss 0.01

    The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a…

  • CVE-2017-4952HigMay 2, 2018
    risk 0.00cvss 7.5epss 0.04

    VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may…

  • CVE-2018-5517HigMay 2, 2018
    risk 0.49cvss 7.5epss 0.02

    On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs.

  • CVE-2018-5514HigMay 2, 2018
    risk 0.49cvss 7.5epss 0.04

    On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual servers when the HTTP2 profile is enabled. There is no control plane exposure to this issue.

  • CVE-2018-5512HigMay 2, 2018
    risk 0.49cvss 7.5epss 0.03

    On F5 BIG-IP 13.1.0-13.1.0.5, when Large Receive Offload (LRO) and SYN cookies are enabled (default settings), undisclosed traffic patterns may cause TMM to restart.

  • CVE-2017-1255HigMay 2, 2018
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.

  • CVE-2018-10647HigMay 2, 2018
    risk 0.51cvss 7.8epss 0.00

    SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service executes "openvpn.exe" using OpenVPN config files located within the current user's %LOCALAPPDATA%\SaferVPN\OvpnConfig directory.…

  • CVE-2018-10646HigMay 2, 2018
    risk 0.51cvss 7.8epss 0.00

    CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The…

  • CVE-2018-10645HigMay 2, 2018
    risk 0.51cvss 7.8epss 0.00

    Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. The "SetProperty" method…

  • CVE-2018-10642HigMay 2, 2018
    risk 0.47cvss 7.2epss 0.07

    Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the…

  • CVE-2018-10260HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.06

    A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.

  • CVE-2018-10258HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.07

    A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2018-10257HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.04

    A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2018-10256HigMay 1, 2018
    risk 0.60cvss 8.8epss 0.03

    A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

  • CVE-2018-10255HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.07

    A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2013-2049HigMay 1, 2018
    risk 0.49cvss 7.5epss 0.01

    Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.

  • CVE-2013-0185HigMay 1, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

  • CVE-2013-0159HigMay 1, 2018
    risk 0.46cvss 7.1epss 0.00

    The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg.