VYPR

CVEs

28,747 total · page 467 of 575

  • CVE-2016-4889HigApr 14, 2017
    risk 0.58cvss 8.8epss 0.04

    ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

  • CVE-2016-3104HigApr 14, 2017
    risk 0.49cvss 7.5epss 0.01

    mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

  • CVE-2016-1713HigApr 14, 2017
    risk 0.55cvss 7.3epss 0.62

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in test/logo/. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6000.

  • CVE-2016-0727HigApr 14, 2017
    risk 0.54cvss 7.8epss 0.01

    The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics directory cleanup.

  • CVE-2017-1205HigApr 14, 2017
    risk 0.57cvss 8.8epss 0.00

    IBM Platform LSF 10.1 contains an unspecified vulnerability that could allow a local user to escalate their privileges and obtain root access. IBM X-Force ID: 123741.

  • CVE-2015-6568HigApr 14, 2017
    risk 0.61cvss 8.8epss 0.12

    Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality.

  • CVE-2015-6567HigApr 14, 2017
    risk 0.61cvss 8.8epss 0.06

    Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.

  • CVE-2017-7643HigApr 14, 2017
    risk 0.54cvss 7.8epss 0.00

    Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.

  • CVE-2017-7456HigApr 14, 2017
    risk 0.53cvss 7.5epss 0.11

    Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

  • CVE-2017-7455HigApr 14, 2017
    risk 0.55cvss 7.5epss 0.40

    Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

  • CVE-2017-7408HigApr 14, 2017
    risk 0.49cvss 7.5epss 0.01

    Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.

  • CVE-2017-7218HigApr 14, 2017
    risk 0.51cvss 7.8epss 0.00

    The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.

  • CVE-2015-8356HigApr 14, 2017
    risk 0.55cvss 8.0epss 0.03

    Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) xls_profile parameter to admin/mcart_xls_import.php or the (2) xls_iblock_id, (3) xls_iblock_section_id, (4) firstRow, (5) titleRow, (6) firstColumn, (7) highestColumn, (8) sku_iblock_id, or (9) xls_iblock_section_id_new parameter to admin/mcart_xls_import_step_2.php.

  • CVE-2017-7869HigApr 14, 2017
    risk 0.49cvss 7.5epss 0.01

    GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.

  • CVE-2017-7868HigApr 14, 2017
    risk 0.49cvss 7.5epss 0.02

    International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.

  • CVE-2017-7867HigApr 14, 2017
    risk 0.49cvss 7.5epss 0.01

    International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.

  • CVE-2016-8727HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.01

    An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker.

  • CVE-2016-8726HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a blank line in the header will cause a segmentation fault in the web server.

  • CVE-2016-8723HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

  • CVE-2016-8712HigApr 13, 2017
    risk 0.53cvss 8.1epss 0.00

    An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300 seconds.

  • CVE-2016-7834HigApr 13, 2017
    risk 0.60cvss 8.8epss 0.39

    SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-ER585, SNC-ER585H, SNC-ZP550, SNC-ZR550, SNC-EP520, SNC-EP521, SNC-ER520, SNC-ER521, SNC-ER521C network cameras with firmware before Ver.1.86.00 and SONY SNC-CX600, SNC-CX600W, SNC-EB600, SNC-EB600B, SNC-EB602R, SNC-EB630, SNC-EB630B, SNC-EB632R, SNC-EM600, SNC-EM601, SNC-EM602R, SNC-EM602RC, SNC-EM630, SNC-EM631, SNC-EM632R, SNC-EM632RC, SNC-VB600, SNC-VB600B, SNC-VB600B5, SNC-VB630, SNC-VB6305, SNC-VB6307, SNC-VB632D, SNC-VB635, SNC-VM600, SNC-VM600B, SNC-VM600B5, SNC-VM601, SNC-VM601B, SNC-VM602R, SNC-VM630, SNC-VM6305, SNC-VM6307, SNC-VM631, SNC-VM632R, SNC-WR600, SNC-WR602, SNC-WR602C, SNC-WR630, SNC-WR632, SNC-WR632C, SNC-XM631, SNC-XM632, SNC-XM636, SNC-XM637, SNC-VB600L, SNC-VM600L, SNC-XM631L, SNC-WR602CL network cameras with firmware before Ver.2.7.2 are prone to sensitive information disclosure. This may allow an attacker on the same local network segment to login to the device with administrative privileges and perform operations on the device.

  • CVE-2015-8619HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.03

    The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).

  • CVE-2015-8567HigApr 13, 2017
    risk 0.50cvss 7.7epss 0.03

    Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).

  • CVE-2015-4646HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.01

    (1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

  • CVE-2013-6648HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).

  • CVE-2017-7853HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.

  • CVE-2016-10326HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

  • CVE-2016-10325HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.

  • CVE-2010-1821HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.

  • CVE-2010-1816HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.

  • CVE-2017-7219HigApr 13, 2017
    risk 0.57cvss 8.8epss 0.02

    A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run arbitrary commands via unspecified vectors.

  • CVE-2016-4970HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.08

    handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

  • CVE-2016-1914HigApr 13, 2017
    risk 0.60cvss 8.8epss 0.03

    Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.

  • CVE-2016-1132HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.00

    Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.

  • CVE-2016-10123HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.

  • CVE-2016-10122HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Firejail does not properly clean environment variables, which allows local users to gain privileges.

  • CVE-2016-10121HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.

  • CVE-2016-10120HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.

  • CVE-2016-10119HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.

  • CVE-2016-10117HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.00

    Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

  • CVE-2015-8284HigApr 13, 2017
    risk 0.61cvss 8.8epss 0.06

    SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.

  • CVE-2015-8270HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.01

    The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).

  • CVE-2015-8107HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.02

    Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

  • CVE-2012-6697HigApr 13, 2017
    risk 0.49cvss 7.5epss 0.01

    InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).

  • CVE-2017-7748HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.00

    In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.

  • CVE-2017-7747HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.01

    In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.

  • CVE-2017-7746HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.02

    In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.

  • CVE-2017-7745HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.00

    In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.

  • CVE-2017-7705HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.01

    In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rpcrdma.c by correctly checking for going beyond the maximum offset.

  • CVE-2017-7704HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.01

    In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dof.c by using a different integer data type and adjusting a return value.