VYPR

CVEs

101,977 total · page 1817 of 2,040

  • CVE-2004-2779HigFeb 20, 2018
    risk 0.49cvss 7.5epss 0.03

    id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an endless loop allocating memory until an OOM condition is reached, leading to denial-of-service (DoS).

  • CVE-2018-7046HigFeb 20, 2018
    risk 0.47cvss 7.2epss 0.06

    Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. …

  • CVE-2018-6941HigFeb 20, 2018
    risk 0.60cvss 8.8epss 0.04

    A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.

  • CVE-2016-6272HigFeb 20, 2018
    risk 0.53cvss 7.5epss 0.21

    XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this…

  • CVE-2017-18192HigFeb 20, 2018
    risk 0.49cvss 7.5epss 0.01

    smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN.

  • CVE-2017-16835HigFeb 20, 2018
    risk 0.49cvss 7.5epss 0.01

    The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.

  • CVE-2018-7254HigFeb 19, 2018
    risk 0.04cvss 7.8epss 0.10

    The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafted CAF file.

  • CVE-2018-7253HigFeb 19, 2018
    risk 0.00cvss 7.8epss 0.03

    The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file.

  • CVE-2016-10008HigFeb 19, 2018
    risk 0.40cvss 7.2epss 0.01

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.

  • CVE-2016-10007HigFeb 19, 2018
    risk 0.40cvss 7.2epss 0.01

    SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.

  • CVE-2018-6592HigFeb 19, 2018
    risk 0.51cvss 7.8epss 0.00

    Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by leveraging improper cleanup of memory used for negotiation key storage.

  • CVE-2017-16670HigFeb 19, 2018
    risk 0.51cvss 7.8epss 0.02

    The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.

  • CVE-2012-0771HigFeb 19, 2018
    risk 0.58cvss 8.8epss 0.05

    Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759.

  • CVE-2017-18191HigFeb 19, 2018
    risk 0.42cvss 7.5epss 0.04

    An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host.…

  • CVE-2018-7219HigFeb 19, 2018
    risk 0.57cvss 8.8epss 0.01

    application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.

  • CVE-2018-1411HigFeb 19, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID:…

  • CVE-2018-1410HigFeb 19, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID:…

  • CVE-2018-1409HigFeb 19, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID:…

  • CVE-2017-16756HigFeb 19, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account.

  • CVE-2018-5379HigFeb 19, 2018
    risk 0.52cvss 7.5epss 0.39

    The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute…

  • CVE-2018-5378HigFeb 19, 2018
    risk 0.52cvss 7.1epss 0.75

    The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

  • CVE-2018-7217HigFeb 18, 2018
    risk 0.57cvss 8.8epss 0.02

    In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or the server side. An attacker can take advantage of this vulnerability and upload malicious executable files to compromise the application, as demonstrated by…

  • CVE-2018-7216HigFeb 18, 2018
    risk 0.55cvss 8.0epss 0.03

    Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF…

  • CVE-2018-7211HigFeb 18, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials.

  • CVE-2018-7210HigFeb 18, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=installLicense URI, as demonstrated by intranet IP addresses and names of guest accounts.

  • CVE-2018-7209HigFeb 18, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/config.xml URI, as demonstrated by intranet URLs for reports.

  • CVE-2018-7208HigFeb 18, 2018
    risk 0.51cvss 7.8epss 0.02

    In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified…

  • CVE-2018-7206HigFeb 18, 2018
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to…

  • CVE-2018-6218HigFeb 16, 2018
    risk 0.46cvss 7.0epss 0.02

    A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.

  • CVE-2018-3609HigFeb 16, 2018
    risk 0.54cvss 8.1epss 0.22

    A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.

  • CVE-2018-7187HigFeb 16, 2018
    risk 0.62cvss 8.8epss 0.63

    The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.

  • CVE-2018-0516HigFeb 16, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in FLET'S v4 / v6 address selection tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0515HigFeb 16, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-18190HigFeb 16, 2018
    risk 0.00cvss 7.5epss 0.03

    A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often…

  • CVE-2018-7176HigFeb 16, 2018
    risk 0.60cvss 8.8epss 0.02

    FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).

  • CVE-2017-14535HigFeb 16, 2018
    risk 0.64cvss 8.8epss 0.50

    trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

  • CVE-2018-6316HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.02

    Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti…

  • CVE-2017-8984HigFeb 15, 2018
    risk 0.58cvss 8.8epss 0.11

    A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.

  • CVE-2017-8983HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.04

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

  • CVE-2017-8982HigFeb 15, 2018
    risk 0.53cvss 7.5epss 0.14

    A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

  • CVE-2017-8980HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.05

    A Remote Disclosure of Information vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8967HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8966HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.03

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8965HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8964HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8963HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8962HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.03

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

  • CVE-2017-8961HigFeb 15, 2018
    risk 0.59cvss 8.8epss 0.19

    A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.

  • CVE-2017-8959HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.01

    An Authentication Bypass vulnerability in HPE MSA 1040 and HPE MSA 2040 SAN Storage in version GL220P008 and earlier and was found.

  • CVE-2017-8958HigFeb 15, 2018
    risk 0.58cvss 8.8epss 0.11

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 and earlier was found.