VYPR

CVEs

101,972 total · page 1826 of 2,040

  • CVE-2018-6384HigJan 31, 2018
    risk 0.51cvss 7.8epss 0.01

    Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

  • CVE-2017-8916HigJan 31, 2018
    risk 0.51cvss 7.8epss 0.00

    In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

  • CVE-2018-1000001HigJan 31, 2018
    risk 0.55cvss 7.8epss 0.13

    In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

  • CVE-2017-1000411HigJan 31, 2018
    risk 0.49cvss 7.5epss 0.02

    OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown. If multiple different flows with…

  • CVE-2018-6412HigJan 31, 2018
    risk 0.00cvss 7.5epss 0.02

    In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

  • CVE-2018-6408HigJan 30, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account.

  • CVE-2018-6407HigJan 30, 2018
    risk 0.51cvss 7.5epss 0.32

    An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device.

  • CVE-2018-6406HigJan 30, 2018
    risk 0.57cvss 8.8epss 0.02

    The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read…

  • CVE-2018-6195HigJan 30, 2018
    risk 0.40cvss 7.2epss 0.04

    admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the…

  • CVE-2018-5441HigJan 30, 2018
    risk 0.51cvss 7.8epss 0.00

    An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed…

  • CVE-2017-1731HigJan 30, 2018
    risk 0.57cvss 8.8epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.

  • CVE-2014-4705HigJan 30, 2018
    risk 0.49cvss 7.5epss 0.01

    Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300 series routers; and WLAN…

  • CVE-2017-17969HigJan 30, 2018
    risk 0.51cvss 7.8epss 0.05

    Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.

  • CVE-2018-6397HigJan 30, 2018
    risk 0.53cvss 7.5epss 0.12

    Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.

  • CVE-2018-6393HigJan 29, 2018
    risk 0.47cvss 7.2epss 0.02

    FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modify SQL tables ... [or] run shell scripts ... once ... logged…

  • CVE-2018-3835HigJan 29, 2018
    risk 0.57cvss 8.8epss 0.02

    An exploitable out of bounds write vulnerability exists in version 2.2 of the Per Face Texture mapping application known as PTEX. The vulnerability is present in the reading of a file without proper parameter checking. The value read in, is not verified to be valid and its use…

  • CVE-2018-6391HigJan 29, 2018
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.

  • CVE-2017-15133HigJan 29, 2018
    risk 0.42cvss 7.5epss 0.02

    A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from accepting new connections.

  • CVE-2018-6388HigJan 29, 2018
    risk 0.61cvss 8.8epss 0.06

    iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.

  • CVE-2018-6383HigJan 29, 2018
    risk 0.61cvss 8.8epss 0.14

    Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different…

  • CVE-2017-12626HigJan 29, 2018
    risk 0.43cvss 7.5epss 0.10

    Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and…

  • CVE-2017-1000356HigJan 29, 2018
    risk 0.51cvss 8.8epss 0.07

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing…

  • CVE-2017-1000354HigJan 29, 2018
    risk 0.50cvss 8.8epss 0.01

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. The `login` command available in the remoting-based CLI stored the encrypted user name of the successfully authenticated user in a…

  • CVE-2018-1364HigJan 29, 2018
    risk 0.53cvss 8.2epss 0.02

    IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449.

  • CVE-2017-4951HigJan 29, 2018
    risk 0.57cvss 8.8epss 0.01

    VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.

  • CVE-2017-1779HigJan 29, 2018
    risk 0.51cvss 7.8epss 0.00

    IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

  • CVE-2018-6008HigJan 29, 2018
    risk 0.55cvss 7.5epss 0.37

    Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.

  • CVE-2018-6007HigJan 29, 2018
    risk 0.60cvss 8.8epss 0.02

    CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.

  • CVE-2018-5720HigJan 29, 2018
    risk 0.60cvss 8.8epss 0.03

    An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify all the settings. This…

  • CVE-2017-18079HigJan 29, 2018
    risk 0.00cvss 7.8epss 0.00

    drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists value can change after it is validated.

  • CVE-2017-18078HigJan 29, 2018
    risk 0.54cvss 7.8epss 0.01

    systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for…

  • CVE-2018-6360HigJan 28, 2018
    risk 0.00cvss 8.8epss 0.03

    mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. For example, an…

  • CVE-2018-6359HigJan 27, 2018
    risk 0.57cvss 8.8epss 0.02

    The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.

  • CVE-2018-6358HigJan 27, 2018
    risk 0.57cvss 8.8epss 0.02

    The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file.

  • CVE-2018-6357HigJan 27, 2018
    risk 0.57cvss 8.8epss 0.01

    The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/admin-ajax.php, with resultant social_widget_icon_array_order XSS.

  • CVE-2018-6353HigJan 27, 2018
    risk 0.00cvss 7.8epss 0.00

    The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended…

  • CVE-2017-18077HigJan 27, 2018
    risk 0.00cvss 7.5epss 0.03

    index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.

  • CVE-2016-2983HigJan 26, 2018
    risk 0.53cvss 8.1epss 0.02

    IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security. IBM X-Force ID: 113999.

  • CVE-2018-6015HigJan 26, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber…

  • CVE-2017-14523HigJan 26, 2018
    risk 0.52cvss 7.5epss 0.08

    WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack

  • CVE-2017-14521HigJan 26, 2018
    risk 0.61cvss 8.8epss 0.07

    In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

  • CVE-2017-12380HigJan 26, 2018
    risk 0.49cvss 7.5epss 0.05

    ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms in…

  • CVE-2017-12376HigJan 26, 2018
    risk 0.51cvss 7.8epss 0.07

    ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input…

  • CVE-2017-12375HigJan 26, 2018
    risk 0.49cvss 7.5epss 0.06

    The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms…

  • CVE-2017-12374HigJan 26, 2018
    risk 0.49cvss 7.5epss 0.05

    The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms…

  • CVE-2017-3768HigJan 26, 2018
    risk 0.49cvss 7.5epss 0.01

    An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common…

  • CVE-2017-18076HigJan 26, 2018
    risk 0.00cvss 7.5epss 0.02

    In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

  • CVE-2018-0507HigJan 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.11 and earlier versions, FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.11 and earlier versions allow an attacker to gain privileges via a Trojan horse DLL in an unspecified…

  • CVE-2018-6323HigJan 26, 2018
    risk 0.54cvss 7.8epss 0.06

    The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial…

  • CVE-2017-14593HigJan 26, 2018
    risk 0.58cvss 8.8epss 0.06

    Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. From…