VYPR

CVEs

101,988 total · page 1797 of 2,040

  • CVE-2017-0358HigApr 13, 2018
    risk 0.54cvss 7.8epss 0.02

    Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.

  • CVE-2018-5511HigApr 13, 2018
    risk 0.51cvss 7.2epss 0.15

    On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

  • CVE-2018-5510HigApr 13, 2018
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers.

  • CVE-2018-5507HigApr 13, 2018
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 4200 and 4300 series blades cannot correctly decrypt ciphertext from established SSL sessions with small MTU.

  • CVE-2018-10066HigApr 13, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malicious OpenVPN server. This may allow the attacker to gain access to the client's…

  • CVE-2017-6155HigApr 13, 2018
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.4.1-11.5.5, or 11.2.1, malformed SPDY or HTTP/2 requests may result in a disruption of service to TMM. Data plane is only exposed when a SPDY or HTTP/2 profile is attached to a virtual server. There is no control plane…

  • CVE-2017-6148HigApr 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of services provided by TMM. The data plane is impacted and exposed only when a SOCKS proxy profile is attached to a Virtual Server.…

  • CVE-2018-10086HigApr 13, 2018
    risk 0.47cvss 7.2epss 0.02

    CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.

  • CVE-2018-10084HigApr 13, 2018
    risk 0.57cvss 8.8epss 0.01

    CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection mechanism can be bypassed.

  • CVE-2018-10083HigApr 13, 2018
    risk 0.49cvss 7.5epss 0.02

    CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter.

  • CVE-2018-10080HigApr 13, 2018
    risk 0.56cvss 8.6epss 0.01

    Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.

  • CVE-2018-6934HigApr 12, 2018
    risk 0.57cvss 8.8epss 0.00

    CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.

  • CVE-2018-6903HigApr 12, 2018
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.

  • CVE-2018-6879HigApr 12, 2018
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.

  • CVE-2018-5254HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.

  • CVE-2015-0153HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.02

    D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.

  • CVE-2015-0151HigApr 12, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

  • CVE-2014-8422HigApr 12, 2018
    risk 0.53cvss 8.1epss 0.02

    The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

  • CVE-2014-8421HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.02

    Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh, (3) apps.sh, (4)…

  • CVE-2014-6412HigApr 12, 2018
    risk 0.46cvss 8.1epss 0.05

    WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

  • CVE-2018-3889HigApr 12, 2018
    risk 0.51cvss 7.8epss 0.01

    A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.

  • CVE-2018-3868HigApr 12, 2018
    risk 0.51cvss 7.8epss 0.01

    A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.

  • CVE-2018-3862HigApr 12, 2018
    risk 0.51cvss 7.8epss 0.01

    A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting

  • CVE-2018-3861HigApr 12, 2018
    risk 0.51cvss 7.8epss 0.01

    A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.

  • CVE-2018-10063HigApr 12, 2018
    risk 0.54cvss 7.8epss 0.10

    The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.

  • CVE-2018-1084HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.03

    corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.

  • CVE-2018-1079HigApr 12, 2018
    risk 0.57cvss 8.7epss 0.01

    pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an…

  • CVE-2018-9118HigApr 12, 2018
    risk 0.56cvss 7.5epss 0.48

    exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.

  • CVE-2017-6910HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.02

    The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community…

  • CVE-2014-6633HigApr 12, 2018
    risk 0.50cvss 8.8epss 0.03

    The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the collection.domain in the webdav…

  • CVE-2014-6309HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.02

    The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling.

  • CVE-2018-9860HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the receiving side to include in the HMAC computation exactly 64K bytes of data following the record buffer, aka an over-read. The MAC…

  • CVE-2018-1030HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.25

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1026.

  • CVE-2018-1029HigApr 12, 2018
    risk 0.52cvss 7.8epss 0.21

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. This CVE ID…

  • CVE-2018-1028HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.20

    A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft…

  • CVE-2018-1027HigApr 12, 2018
    risk 0.52cvss 7.8epss 0.19

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel, Microsoft Office. This CVE ID is unique from…

  • CVE-2018-1026HigApr 12, 2018
    risk 0.61cvss 8.8epss 0.42

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.

  • CVE-2018-1023HigApr 12, 2018
    risk 0.50cvss 7.5epss 0.15

    A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.

  • CVE-2018-1020HigApr 12, 2018
    risk 0.50cvss 7.5epss 0.16

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from…

  • CVE-2018-1019HigApr 12, 2018
    risk 0.43cvss 7.5epss 0.16

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0979,…

  • CVE-2018-1018HigApr 12, 2018
    risk 0.50cvss 7.5epss 0.16

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-0997,…

  • CVE-2018-1016HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.24

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…

  • CVE-2018-1015HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.24

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…

  • CVE-2018-1013HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.24

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…

  • CVE-2018-1012HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.24

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…

  • CVE-2018-1011HigApr 12, 2018
    risk 0.52cvss 7.8epss 0.20

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-2018-0920,…

  • CVE-2018-1010HigApr 12, 2018
    risk 0.60cvss 8.8epss 0.41

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…

  • CVE-2018-1009HigApr 12, 2018
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1,…

  • CVE-2018-1008HigApr 12, 2018
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT…

  • CVE-2018-1004HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.19

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server…