VYPR

CVEs

101,977 total · page 1805 of 2,040

  • CVE-2018-1238HigMar 27, 2018
    risk 0.49cvss 7.5epss 0.02

    Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user, with network access…

  • CVE-2018-1205HigMar 27, 2018
    risk 0.49cvss 7.5epss 0.01

    Dell EMC ScaleIO, versions prior to 2.5, do not properly handle some packet data in the MDM service. As a result, a remote attacker could potentially send specifically crafted packet data to the MDM service causing it to crash.

  • CVE-2018-7700HigMar 27, 2018
    risk 0.63cvss 8.8epss 0.75

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

  • CVE-2018-7195HigMar 27, 2018
    risk 0.53cvss 8.1epss 0.01

    Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.

  • CVE-2018-6766HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.01

    Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's…

  • CVE-2018-6765HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.01

    Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the…

  • CVE-2018-8764HigMar 27, 2018
    risk 0.50cvss 8.8epss 0.01

    Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

  • CVE-2018-8718HigMar 27, 2018
    risk 0.49cvss 8.0epss 0.07

    Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

  • CVE-2018-1267HigMar 27, 2018
    risk 0.53cvss 8.1epss 0.01

    Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the…

  • CVE-2018-1266HigMar 27, 2018
    risk 0.53cvss 8.1epss 0.01

    Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the…

  • CVE-2018-1231HigMar 27, 2018
    risk 0.57cvss 8.8epss 0.01

    Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.

  • CVE-2014-0486HigMar 27, 2018
    risk 0.49cvss 7.5epss 0.03

    Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.

  • CVE-2017-12310HigMar 27, 2018
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to conduct additional…

  • CVE-2018-9054HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100284c.

  • CVE-2018-9053HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf10026cc.

  • CVE-2018-9052HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c.

  • CVE-2018-9051HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002021.

  • CVE-2018-9050HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.

  • CVE-2018-9049HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002833.

  • CVE-2018-9048HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100282c.

  • CVE-2018-9047HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002841.

  • CVE-2018-9046HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100282d.

  • CVE-2018-9045HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002849.

  • CVE-2018-9044HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.

  • CVE-2018-9043HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.

  • CVE-2018-9042HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.

  • CVE-2018-9041HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

  • CVE-2018-9040HigMar 27, 2018
    risk 0.51cvss 7.8epss 0.00

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.

  • CVE-2018-8802HigMar 26, 2018
    risk 0.53cvss 8.1epss 0.01

    SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

  • CVE-2018-7658HigMar 26, 2018
    risk 0.55cvss 7.5epss 0.40

    NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.

  • CVE-2017-12410HigMar 26, 2018
    risk 0.48cvss 7.4epss 0.00

    It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders. Successful exploitation results in…

  • CVE-2017-18249HigMar 26, 2018
    risk 0.00cvss 7.0epss 0.00

    The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

  • CVE-2018-1213HigMar 26, 2018
    risk 0.60cvss 8.8epss 0.02

    Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send…

  • CVE-2015-7434HigMar 26, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107863.

  • CVE-2015-7433HigMar 26, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.

  • CVE-2015-7432HigMar 26, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

  • CVE-2015-5039HigMar 26, 2018
    risk 0.48cvss 7.4epss 0.01

    The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain…

  • CVE-2017-6278HigMar 26, 2018
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Tegra kernel contains a vulnerability in the CORE DVFS Thermal driver where there is the potential to read or write a buffer using an index or pointer that references a memory location after the end of the buffer, which may lead to a denial of service or possible…

  • CVE-2018-1303HigMar 26, 2018
    risk 0.54cvss 7.5epss 0.71

    A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The…

  • CVE-2017-15715HigMar 26, 2018
    risk 0.60cvss 8.1epss 0.86

    In Apache httpd 2.4.0 to 2.4.29, the expression specified in could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally…

  • CVE-2017-15710HigMar 26, 2018
    risk 0.50cvss 7.5epss 0.18

    In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present…

  • CVE-2018-5470HigMar 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified, which may allow an authorized local user to execute arbitrary code and escalate their level of privileges.

  • CVE-2018-5466HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5464HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5462HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.02

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5458HigMar 26, 2018
    risk 0.49cvss 7.5epss 0.01

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.

  • CVE-2018-5454HigMar 26, 2018
    risk 0.53cvss 8.1epss 0.04

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could allow an attacker to remotely execute arbitrary code during runtime.

  • CVE-2018-8979HigMar 25, 2018
    risk 0.60cvss 8.8epss 0.01

    Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.

  • CVE-2018-8817HigMar 25, 2018
    risk 0.60cvss 8.8epss 0.03

    Wampserver before 3.1.3 has CSRF in add_vhost.php.

  • CVE-2018-9014HigMar 25, 2018
    risk 0.49cvss 7.5epss 0.01

    dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.