VYPR

CVEs

101,977 total · page 1814 of 2,040

  • CVE-2018-7641HigMar 2, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "32 bits colors" case, aka case 32.

  • CVE-2018-7640HigMar 2, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a Monochrome case, aka case 1.

  • CVE-2018-7639HigMar 2, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "16 bits colors" case, aka case 16.

  • CVE-2018-7638HigMar 2, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "256 colors" case, aka case 8.

  • CVE-2018-7637HigMar 2, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "16 colors" case, aka case 4.

  • CVE-2018-1170HigMar 2, 2018
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer-Link Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2018-1169HigMar 2, 2018
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…

  • CVE-2018-7634HigMar 1, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers. By making a CSRF attack, an attacker could make a victim change his registered e-mail address on the…

  • CVE-2017-6930HigMar 1, 2018
    risk 0.53cvss 8.1epss 0.01

    In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of…

  • CVE-2017-6926HigMar 1, 2018
    risk 0.53cvss 8.1epss 0.01

    In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by the fact that the comment system must be…

  • CVE-2018-7590HigMar 1, 2018
    risk 0.57cvss 8.8epss 0.01

    CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation.

  • CVE-2018-7589HigMar 1, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.

  • CVE-2018-7588HigMar 1, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image.

  • CVE-2018-7587HigMar 1, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure in load_bmp in CImg.h.

  • CVE-2018-7586HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.02

    In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.

  • CVE-2017-15134HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.04

    A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially…

  • CVE-2018-7048HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request.

  • CVE-2017-18209HigMar 1, 2018
    risk 0.57cvss 8.8epss 0.03

    In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory.

  • CVE-2017-9286HigMar 1, 2018
    risk 0.51cvss 7.8epss 0.01

    The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.

  • CVE-2017-9274HigMar 1, 2018
    risk 0.51cvss 7.8epss 0.02

    A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.

  • CVE-2017-9270HigMar 1, 2018
    risk 0.57cvss 8.7epss 0.02

    In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.

  • CVE-2017-9269HigMar 1, 2018
    risk 0.50cvss 7.7epss 0.02

    In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

  • CVE-2017-7436HigMar 1, 2018
    risk 0.53cvss 8.1epss 0.02

    In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

  • CVE-2017-7435HigMar 1, 2018
    risk 0.53cvss 8.1epss 0.02

    In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

  • CVE-2017-14798HigMar 1, 2018
    risk 0.51cvss 7.3epss 0.01

    A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

  • CVE-2018-7579HigMar 1, 2018
    risk 0.47cvss 7.2epss 0.01

    \application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.

  • CVE-2018-7550HigMar 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.

  • CVE-2018-5314HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.03

    Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN…

  • CVE-2018-2367HigMar 1, 2018
    risk 0.57cvss 8.8epss 0.02

    ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed…

  • CVE-2017-6154HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.02

    On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memory under some circumstances when processing undisclosed types of data on systems with 48 or more CPU cores.

  • CVE-2017-6150HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.02

    Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disabled (default), some specific large fragmented packets may restart the Traffic Management Microkernel (TMM).

  • CVE-2018-6947HigFeb 28, 2018
    risk 0.54cvss 7.8epss 0.03

    An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8…

  • CVE-2015-5079HigFeb 28, 2018
    risk 0.53cvss 7.5epss 0.17

    Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.

  • CVE-2015-4117HigFeb 28, 2018
    risk 0.61cvss 8.8epss 0.11

    Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

  • CVE-2016-0295HigFeb 28, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.

  • CVE-2016-0291HigFeb 28, 2018
    risk 0.58cvss 8.8epss 0.04

    IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.

  • CVE-2017-9447HigFeb 28, 2018
    risk 0.49cvss 7.5epss 0.02

    In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness…

  • CVE-2017-12191HigFeb 28, 2018
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could…

  • CVE-2018-7482HigFeb 28, 2018
    risk 0.49cvss 7.5epss 0.02

    The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname…

  • CVE-2018-7549HigFeb 27, 2018
    risk 0.49cvss 7.5epss 0.03

    In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

  • CVE-2017-18205HigFeb 27, 2018
    risk 0.53cvss 8.1epss 0.02

    In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

  • CVE-2014-10070HigFeb 27, 2018
    risk 0.51cvss 7.8epss 0.01

    zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in…

  • CVE-2018-7467HigFeb 27, 2018
    risk 0.50cvss 7.5epss 0.10

    AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.

  • CVE-2017-7671HigFeb 27, 2018
    risk 0.49cvss 7.5epss 0.02

    There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.

  • CVE-2017-5660HigFeb 27, 2018
    risk 0.56cvss 8.6epss 0.02

    There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.

  • CVE-2018-7541HigFeb 27, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.

  • CVE-2018-6535HigFeb 27, 2018
    risk 0.00cvss 8.1epss 0.01

    An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.

  • CVE-2018-6533HigFeb 27, 2018
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any…

  • CVE-2018-6532HigFeb 27, 2018
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.

  • CVE-2017-15693HigFeb 27, 2018
    risk 0.00cvss 7.5epss 0.03

    In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if…