VYPR

CVEs

101,988 total · page 1793 of 2,040

  • CVE-2018-10254HigApr 21, 2018
    risk 0.51cvss 7.8epss 0.01

    Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.

  • CVE-2018-10253HigApr 21, 2018
    risk 0.52cvss 7.5epss 0.08

    Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.

  • CVE-2018-10173HigApr 20, 2018
    risk 0.58cvss 8.8epss 0.05

    Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.

  • CVE-2018-10079HigApr 20, 2018
    risk 0.54cvss 7.8epss 0.01

    Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.

  • CVE-2017-2825HigApr 20, 2018
    risk 0.46cvss 7.0epss 0.04

    In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to…

  • CVE-2014-0950HigApr 20, 2018
    risk 0.46cvss 7.1epss 0.02

    Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through…

  • CVE-2014-0927HigApr 20, 2018
    risk 0.53cvss 8.1epss 0.02

    The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.

  • CVE-2014-0900HigApr 20, 2018
    risk 0.57cvss 8.8epss 0.00

    The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.

  • CVE-2014-6111HigApr 20, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows…

  • CVE-2014-10073HigApr 20, 2018
    risk 0.49cvss 7.5epss 0.02

    The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.

  • CVE-2018-10249HigApr 20, 2018
    risk 0.57cvss 8.8epss 0.01

    baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.

  • CVE-2017-8315HigApr 20, 2018
    risk 0.49cvss 7.5epss 0.02

    Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

  • CVE-2018-1292HigApr 20, 2018
    risk 0.53cvss 8.1epss 0.02

    Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.

  • CVE-2018-1291HigApr 20, 2018
    risk 0.53cvss 8.1epss 0.02

    Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' query…

  • CVE-2018-1289HigApr 20, 2018
    risk 0.57cvss 8.8epss 0.03

    In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statements. A hacker/user…

  • CVE-2018-6960HigApr 20, 2018
    risk 0.57cvss 8.8epss 0.03

    VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

  • CVE-2018-0564HigApr 20, 2018
    risk 0.53cvss 8.1epss 0.02

    Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0.11, EC-CUBE 3.0.12, EC-CUBE 3.0.12-p1, EC-CUBE 3.0.13,…

  • CVE-2018-10201HigApr 20, 2018
    risk 0.55cvss 7.5epss 0.46

    An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with…

  • CVE-2018-0259HigApr 19, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF…

  • CVE-2018-0255HigApr 19, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2018-0241HigApr 19, 2018
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that…

  • CVE-2018-0240HigApr 19, 2018
    risk 0.56cvss 8.6epss 0.04

    Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device,…

  • CVE-2018-0239HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to cause an…

  • CVE-2018-0233HigApr 19, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device,…

  • CVE-2018-0231HigApr 19, 2018
    risk 0.56cvss 8.6epss 0.05

    A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial…

  • CVE-2018-0230HigApr 19, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting…

  • CVE-2018-0228HigApr 19, 2018
    risk 0.56cvss 8.6epss 0.04

    A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The…

  • CVE-2018-0227HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL…

  • CVE-2018-3843HigApr 19, 2018
    risk 0.59cvss 8.8epss 0.24

    An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations. A specially crafted PDF document can lead to an object of invalid type to be dereferenced, which can potentially lead to sensitive…

  • CVE-2018-3842HigApr 19, 2018
    risk 0.57cvss 8.8epss 0.03

    An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary…

  • CVE-2018-10236HigApr 19, 2018
    risk 0.47cvss 7.2epss 0.02

    POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an attacker can control the value of $data['name'] with no restrictions, and this value is written to the FCPATH.$file file.

  • CVE-2018-10235HigApr 19, 2018
    risk 0.47cvss 7.2epss 0.02

    POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diy\module\member\models\Member_model.php and write this…

  • CVE-2018-8118HigApr 19, 2018
    risk 0.50cvss 7.5epss 0.09

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.

  • CVE-2018-7920HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.01

    Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200R006C10SPC300 devices have an improper resource management vulnerability. Due to the improper implementation of ACL mechanism, a remote attacker may send TCP…

  • CVE-2018-10188HigApr 19, 2018
    risk 0.54cvss 8.8epss 0.04

    phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

  • CVE-2017-3776HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.01

    Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.

  • CVE-2017-17310HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.01

    Electronic Numbers to URI Mapping (ENUM) module in some Huawei products DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a buffer error…

  • CVE-2018-6306HigApr 19, 2018
    risk 0.51cvss 7.8epss 0.03

    Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.

  • CVE-2018-1146HigApr 19, 2018
    risk 0.51cvss 7.5epss 0.29

    A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to set.cgi. When enabled the telnet session requires no password and provides root access.

  • CVE-2018-10222HigApr 19, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.

  • CVE-2018-10220HigApr 19, 2018
    risk 0.57cvss 8.8epss 0.02

    Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote File Inclusion emulation

  • CVE-2018-2876HigApr 19, 2018
    risk 0.46cvss 7.1epss 0.01

    Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: RIB Kernal(Apache Commons Collections)). The supported version that is affected is 13.2. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2018-2862HigApr 19, 2018
    risk 0.46cvss 7.1epss 0.01

    Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: User Interface). Supported versions that are affected are 13.3.8, 13.4.9, 14.0.4 and 14.1.3. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2018-2860HigApr 19, 2018
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure…

  • CVE-2018-2856HigApr 19, 2018
    risk 0.53cvss 8.1epss 0.02

    Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability…

  • CVE-2018-2855HigApr 19, 2018
    risk 0.53cvss 8.1epss 0.02

    Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged…

  • CVE-2018-2851HigApr 19, 2018
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Enterprise Management Console). Supported versions that are affected are 1.6 and 1.7. Easily exploitable vulnerability allows low privileged attacker with…

  • CVE-2018-2850HigApr 19, 2018
    risk 0.48cvss 7.3epss 0.01

    Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.x. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2018-2849HigApr 19, 2018
    risk 0.50cvss 7.7epss 0.01

    Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supported versions that are affected are 16.2 and 17.1 - 17.12. Easily exploitable vulnerability allows low privileged…

  • CVE-2018-2848HigApr 19, 2018
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Client Application Loader). Supported versions that are affected are 1.6 and 1.7. Easily exploitable vulnerability allows unauthenticated attacker with…