VYPR

CVEs

101,977 total · page 1821 of 2,040

  • CVE-2018-0742HigFeb 15, 2018
    risk 0.51cvss 7.8epss 0.01

    The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the…

  • CVE-2017-13273HigFeb 15, 2018
    risk 0.46cvss 7.0epss 0.00

    In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID:…

  • CVE-2017-6230HigFeb 14, 2018
    risk 0.57cvss 8.8epss 0.02

    Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective…

  • CVE-2017-6229HigFeb 14, 2018
    risk 0.57cvss 8.8epss 0.02

    Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x or before contain authenticated Root Command Injection in the CLI that could allow authenticated…

  • CVE-2018-7034HigFeb 14, 2018
    risk 0.49cvss 7.5epss 0.02

    TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

  • CVE-2018-7032HigFeb 14, 2018
    risk 0.49cvss 7.5epss 0.02

    webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

  • CVE-2017-1499HigFeb 14, 2018
    risk 0.57cvss 8.8epss 0.02

    IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.

  • CVE-2018-2395HigFeb 14, 2018
    risk 0.57cvss 8.8epss 0.02

    Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.

  • CVE-2018-2393HigFeb 14, 2018
    risk 0.53cvss 7.5epss 0.18

    Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

  • CVE-2018-2392HigFeb 14, 2018
    risk 0.55cvss 7.5epss 0.41

    Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

  • CVE-2018-2381HigFeb 14, 2018
    risk 0.57cvss 8.8epss 0.01

    SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2018-2376HigFeb 14, 2018
    risk 0.53cvss 8.1epss 0.01

    In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.

  • CVE-2018-2375HigFeb 14, 2018
    risk 0.53cvss 8.1epss 0.01

    In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.

  • CVE-2018-2373HigFeb 14, 2018
    risk 0.49cvss 7.5epss 0.01

    Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0.

  • CVE-2018-6910HigFeb 13, 2018
    risk 0.50cvss 7.5epss 0.19

    DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

  • CVE-2018-6954HigFeb 13, 2018
    risk 0.51cvss 7.8epss 0.01

    systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory…

  • CVE-2017-1714HigFeb 13, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633.

  • CVE-2017-1711HigFeb 13, 2018
    risk 0.51cvss 7.8epss 0.01

    IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.

  • CVE-2018-6952HigFeb 13, 2018
    risk 0.49cvss 7.5epss 0.08

    A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

  • CVE-2018-6951HigFeb 13, 2018
    risk 0.49cvss 7.5epss 0.09

    An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

  • CVE-2018-6293HigFeb 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Arbitrary File Read in Saperion Web Client version 7.5.2 83166.

  • CVE-2017-9970HigFeb 12, 2018
    risk 0.47cvss 7.2epss 0.05

    A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to…

  • CVE-2017-9967HigFeb 12, 2018
    risk 0.51cvss 7.8epss 0.00

    A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in…

  • CVE-2017-9963HigFeb 12, 2018
    risk 0.53cvss 8.1epss 0.00

    A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type…

  • CVE-2017-17723HigFeb 12, 2018
    risk 0.53cvss 8.1epss 0.02

    In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

  • CVE-2018-1214HigFeb 12, 2018
    risk 0.46cvss 7.0epss 0.01

    Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management…

  • CVE-2018-6927HigFeb 12, 2018
    risk 0.00cvss 7.8epss 0.01

    The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.

  • CVE-2017-13247HigFeb 12, 2018
    risk 0.51cvss 7.8epss 0.00

    In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android…

  • CVE-2017-13246HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.

  • CVE-2017-13245HigFeb 12, 2018
    risk 0.51cvss 7.8epss 0.00

    A elevation of privilege vulnerability in the Upstream kernel audio driver. Product: Android. Versions: Android kernel. ID: A-64315347.

  • CVE-2017-13244HigFeb 12, 2018
    risk 0.51cvss 7.8epss 0.00

    A elevation of privilege vulnerability in the Upstream kernel easel. Product: Android. Versions: Android kernel. ID: A-62678986.

  • CVE-2017-13243HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991.

  • CVE-2017-13242HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-62672248.

  • CVE-2017-13241HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    A information disclosure vulnerability in the Android media framework (libstagefright_soft_avcenc). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-69065651.

  • CVE-2017-13240HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    A information disclosure vulnerability in the Android framework (crypto framework). Product: Android. Versions: 8.0, 8.1. ID: A-68694819.

  • CVE-2017-13239HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.00

    A information disclosure vulnerability in the Android framework (ui framework). Product: Android. Versions: 8.0. ID: A-66244132.

  • CVE-2017-13236HigFeb 12, 2018
    risk 0.54cvss 7.8epss 0.01

    In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1.…

  • CVE-2017-13232HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.…

  • CVE-2017-13231HigFeb 12, 2018
    risk 0.51cvss 7.8epss 0.00

    In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID:…

  • CVE-2017-13230HigFeb 12, 2018
    risk 0.57cvss 8.8epss 0.02

    In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2017-13228HigFeb 12, 2018
    risk 0.57cvss 8.8epss 0.01

    In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2016-9570HigFeb 12, 2018
    risk 0.49cvss 7.5epss 0.01

    cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe.

  • CVE-2018-6926HigFeb 12, 2018
    risk 0.47cvss 7.2epss 0.02

    In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The…

  • CVE-2016-8742HigFeb 12, 2018
    risk 0.54cvss 7.8epss 0.02

    The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service…

  • CVE-2016-5397HigFeb 12, 2018
    risk 0.58cvss 8.8epss 0.07

    The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

  • CVE-2017-18179HigFeb 12, 2018
    risk 0.57cvss 8.8epss 0.03

    Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.

  • CVE-2018-6889HigFeb 12, 2018
    risk 0.61cvss 8.8epss 0.07

    An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.

  • CVE-2018-6888HigFeb 12, 2018
    risk 0.55cvss 8.0epss 0.02

    An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack…

  • CVE-2018-6860HigFeb 12, 2018
    risk 0.57cvss 8.8epss 0.03

    Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture.

  • CVE-2018-1000058HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.03

    Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore…