VYPR

CVEs

101,977 total · page 1810 of 2,040

  • CVE-2018-0903HigMar 14, 2018
    risk 0.52cvss 7.8epss 0.16

    Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution Vulnerability".

  • CVE-2018-0902HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.01

    The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way the kernel-mode driver validates and enforces…

  • CVE-2018-0893HigMar 14, 2018
    risk 0.51cvss 7.5epss 0.27

    Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876,…

  • CVE-2018-0889HigMar 14, 2018
    risk 0.50cvss 7.5epss 0.16

    Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876,…

  • CVE-2018-0886HigMar 14, 2018
    risk 0.55cvss 7.0epss 0.82

    The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows…

  • CVE-2018-0884HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.01

    Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to how objects are handled in memory, aka "Windows Security Feature Bypass Vulnerability". This CVE…

  • CVE-2018-0883HigMar 14, 2018
    risk 0.50cvss 7.5epss 0.15

    Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how file…

  • CVE-2018-0882HigMar 14, 2018
    risk 0.49cvss 7.0epss 0.03

    The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is…

  • CVE-2018-0881HigMar 14, 2018
    risk 0.46cvss 7.0epss 0.01

    The Microsoft Video Control in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege due to how…

  • CVE-2018-0880HigMar 14, 2018
    risk 0.49cvss 7.0epss 0.03

    The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is…

  • CVE-2018-0879HigMar 14, 2018
    risk 0.49cvss 7.5epss 0.08

    Microsoft Edge in Windows 10 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".

  • CVE-2018-0877HigMar 14, 2018
    risk 0.54cvss 7.8epss 0.03

    The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how file paths are managed, aka "Windows Desktop Bridge VFS Elevation of Privilege…

  • CVE-2018-0876HigMar 14, 2018
    risk 0.50cvss 7.5epss 0.16

    Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0889,…

  • CVE-2018-0875HigMar 14, 2018
    risk 0.50cvss 7.5epss 0.09

    .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".

  • CVE-2018-0874HigMar 14, 2018
    risk 0.43cvss 7.5epss 0.16

    ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID…

  • CVE-2018-0873HigMar 14, 2018
    risk 0.43cvss 7.5epss 0.16

    ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is…

  • CVE-2018-0872HigMar 14, 2018
    risk 0.43cvss 7.5epss 0.16

    ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID…

  • CVE-2018-0868HigMar 14, 2018
    risk 0.46cvss 7.0epss 0.01

    Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability…

  • CVE-2018-0817HigMar 14, 2018
    risk 0.46cvss 7.0epss 0.01

    The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation…

  • CVE-2018-0816HigMar 14, 2018
    risk 0.46cvss 7.0epss 0.01

    The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation…

  • CVE-2018-0815HigMar 14, 2018
    risk 0.46cvss 7.0epss 0.01

    The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Windows 7 SP1 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows GDI Elevation of Privilege Vulnerability". This CVE is unique…

  • CVE-2018-0808HigMar 14, 2018
    risk 0.49cvss 7.5epss 0.08

    ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.

  • CVE-2018-0787HigMar 14, 2018
    risk 0.58cvss 8.8epss 0.10

    ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".

  • CVE-2018-6875HigMar 14, 2018
    risk 0.49cvss 7.5epss 0.01

    Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.

  • CVE-2018-1000130HigMar 14, 2018
    risk 0.52cvss 8.1epss 0.73

    A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.

  • CVE-2018-8100HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.01

    The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml.

  • CVE-2018-1437HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.02

    IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the…

  • CVE-2018-1435HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.03

    IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.

  • CVE-2018-1386HigMar 14, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208.

  • CVE-2018-1000127HigMar 13, 2018
    risk 0.00cvss 7.5epss 0.02

    memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to…

  • CVE-2018-1000126HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web…

  • CVE-2018-1227HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain for the Concourse CI (concourse-dot-ci) open source project…

  • CVE-2017-16251HigMar 13, 2018
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an attacker to execute arbitrary code within…

  • CVE-2018-6305HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Denial of service in Gemalto's Sentinel LDK RTE version before 7.65

  • CVE-2018-6304HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.02

    Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service

  • CVE-2018-6303HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Denial of service by uploading malformed firmware in Hanwha Techwin Smartcams

  • CVE-2018-6302HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Denial of service by blocking of new camera registration on the cloud server in Hanwha Techwin Smartcams

  • CVE-2018-6301HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Arbitrary camera access and monitoring via cloud in Hanwha Techwin Smartcams

  • CVE-2017-1002102HigMar 13, 2018
    risk 0.46cvss 7.1epss 0.01

    In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

  • CVE-2017-1002101HigMar 13, 2018
    risk 0.58cvss 8.8epss 0.12

    In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including…

  • CVE-2018-1057HigMar 13, 2018
    risk 0.58cvss 8.8epss 0.10

    On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg…

  • CVE-2018-1000093HigMar 13, 2018
    risk 0.57cvss 8.8epss 0.02

    CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution and a takeover of the…

  • CVE-2018-1000092HigMar 13, 2018
    risk 0.57cvss 8.8epss 0.00

    CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page.…

  • CVE-2018-1000091HigMar 13, 2018
    risk 0.57cvss 8.8epss 0.03

    KadNode version version 2.2.0 contains a Buffer Overflow vulnerability in Arguments when starting up the binary that can result in Control of program execution flow, leading to remote code execution.

  • CVE-2018-1000090HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file.

  • CVE-2018-1000089HigMar 13, 2018
    risk 0.41cvss 7.4epss 0.01

    Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you…

  • CVE-2018-1000086HigMar 13, 2018
    risk 0.50cvss 8.8epss 0.01

    NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/nprapps/pym.js/blob/master/src/pym.js#L573 that can result in Arbitrary javascript code execution.…

  • CVE-2018-1000082HigMar 13, 2018
    risk 0.57cvss 8.8epss 0.01

    Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is…

  • CVE-2018-1000081HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter ..

  • CVE-2018-1000075HigMar 13, 2018
    risk 0.42cvss 7.5epss 0.05

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar…