VYPR

CVEs

28,730 total · page 470 of 575

  • CVE-2016-5057HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.

  • CVE-2016-5056HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.

  • CVE-2016-5054HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.

  • CVE-2016-5052HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.

  • CVE-2016-5051HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.

  • CVE-2016-4319HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.00

    Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

  • CVE-2016-1516HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.01

    OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.

  • CVE-2015-8258HigApr 10, 2017
    risk 0.53cvss 7.5epss 0.17

    AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."

  • CVE-2015-8255HigApr 10, 2017
    risk 0.60cvss 8.8epss 0.00

    AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.

  • CVE-2015-7274HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.02

    Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.

  • CVE-2015-7270HigApr 10, 2017
    risk 0.51cvss 7.8epss 0.01

    Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.

  • CVE-2015-7265HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.

  • CVE-2015-7263HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.

  • CVE-2015-7260HigApr 10, 2017
    risk 0.51cvss 7.8epss 0.00

    Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.

  • CVE-2015-6028HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.00

    Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

  • CVE-2015-2889HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.01

    Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a Settings URL.

  • CVE-2015-2886HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.

  • CVE-2015-2884HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics.net URLs, stream.m3u8 URIs, and cam_service_enable.cgi.

  • CVE-2015-2880HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.01

    TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.

  • CVE-2014-2960HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.00

    Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.

  • CVE-2017-7605HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.

  • CVE-2017-7604HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.

  • CVE-2017-7603HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.

  • CVE-2017-7602HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-7601HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-7600HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-7599HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-7598HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.01

    tif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.

  • CVE-2017-7597HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-7596HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-7592HigApr 9, 2017
    risk 0.51cvss 7.8epss 0.00

    The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-6033HigApr 7, 2017
    risk 0.51cvss 7.8epss 0.00

    A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.

  • CVE-2017-6019HigApr 7, 2017
    risk 0.53cvss 7.5epss 0.20

    An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.

  • CVE-2017-0583HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Qualcomm CP access driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and because of vulnerability specific details which limit the impact of the issue. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32068683. References: QC-CR#1103788.

  • CVE-2017-0582HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the HTC OEM fastboot command could enable a local malicious application to execute arbitrary code within the context of the sensor hub. This issue is rated as Moderate because it first requires exploitation of separate vulnerabilities. Product: Android. Versions: Kernel-3.10. Android ID: A-33178836.

  • CVE-2017-0581HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Synaptics Touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-34614485.

  • CVE-2017-0580HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Synaptics Touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-34325986.

  • CVE-2017-0579HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34125463. References: QC-CR#1115406.

  • CVE-2017-0578HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the DTS sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-33964406.

  • CVE-2017-0577HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33842951.

  • CVE-2017-0576HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089.

  • CVE-2017-0575HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32658595. References: QC-CR#1103099.

  • CVE-2017-0574HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34624457. References: B-RB#113189.

  • CVE-2017-0573HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34469904. References: B-RB#91539.

  • CVE-2017-0572HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-34198931. References: B-RB#112597.

  • CVE-2017-0571HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34203305. References: B-RB#111541.

  • CVE-2017-0570HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199963. References: B-RB#110688.

  • CVE-2017-0569HigApr 7, 2017
    risk 0.49cvss 7.0epss 0.03

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34198729. References: B-RB#110666.

  • CVE-2017-0568HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34197514. References: B-RB#112600.

  • CVE-2017-0567HigApr 7, 2017
    risk 0.46cvss 7.0epss 0.00

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32125310. References: B-RB#112575.