VYPR

CVEs

28,669 total · page 477 of 574

  • CVE-2017-3851HigMar 22, 2017
    risk 0.49cvss 7.5epss 0.08

    A Directory Traversal vulnerability in the web framework code of the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an unauthenticated, remote attacker to read any file from the CAF in the virtual instance running on the affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting crafted requests to the CAF web interface. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52302.

  • CVE-2017-7231HigMar 22, 2017
    risk 0.51cvss 7.8epss 0.00

    pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially crafted png file. This issue affects the 'process()' function of the 'pngdefry.c' source file.

  • CVE-2017-7227HigMar 22, 2017
    risk 0.49cvss 7.5epss 0.00

    GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.

  • CVE-2017-7225HigMar 22, 2017
    risk 0.49cvss 7.5epss 0.00

    The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash.

  • CVE-2017-7223HigMar 22, 2017
    risk 0.49cvss 7.5epss 0.00

    GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash.

  • CVE-2017-6971HigMar 22, 2017
    risk 0.63cvss 8.8epss 0.29

    AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault ID ENG-104862.

  • CVE-2017-6970HigMar 22, 2017
    risk 0.58cvss 8.4epss 0.01

    AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.

  • CVE-2014-9839HigMar 22, 2017
    risk 0.49cvss 7.5epss 0.00

    magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access).

  • CVE-2014-9835HigMar 22, 2017
    risk 0.51cvss 7.8epss 0.00

    Heap overflow in ImageMagick 6.8.9-9 via a crafted wpf file.

  • CVE-2014-9834HigMar 22, 2017
    risk 0.51cvss 7.8epss 0.00

    Heap overflow in ImageMagick 6.8.9-9 via a crafted pict file.

  • CVE-2014-9833HigMar 22, 2017
    risk 0.51cvss 7.8epss 0.00

    Heap overflow in ImageMagick 6.8.9-9 via a crafted psd file.

  • CVE-2014-9832HigMar 22, 2017
    risk 0.51cvss 7.8epss 0.00

    Heap overflow in ImageMagick 6.8.9-9 via a crafted pcx file.

  • CVE-2017-5874HigMar 22, 2017
    risk 0.57cvss 8.8epss 0.00

    CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.

  • CVE-2017-3849HigMar 21, 2017
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS XE Software (possibly 3.7 through 3.18, and 16) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted autonomic network channel discovery packet to a device that has all the following characteristics: (1) running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature; (2) configured as an autonomic registrar; (3) has a whitelist configured. An exploit could allow the attacker to cause the affected device to reload. Note: Autonomic networking should be configured with a whitelist. Do not remove the whitelist as a workaround. Cisco Bug IDs: CSCvc42717.

  • CVE-2016-6650HigMar 21, 2017
    risk 0.49cvss 7.5epss 0.01

    EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.

  • CVE-2016-4504HigMar 21, 2017
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.

  • CVE-2017-7208HigMar 21, 2017
    risk 0.46cvss 7.1epss 0.00

    The decode_residual function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.

  • CVE-2017-7206HigMar 21, 2017
    risk 0.46cvss 7.1epss 0.00

    The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.

  • CVE-2016-4929HigMar 20, 2017
    risk 0.57cvss 8.8epss 0.02

    Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.

  • CVE-2016-4928HigMar 20, 2017
    risk 0.57cvss 8.8epss 0.00

    Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.

  • CVE-2016-4927HigMar 20, 2017
    risk 0.53cvss 8.1epss 0.00

    Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.

  • CVE-2016-6816HigMar 20, 2017
    risk 0.42cvss 7.1epss 0.03

    The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

  • CVE-2017-6803HigMar 20, 2017
    risk 0.60cvss 8.8epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.

  • CVE-2017-6318HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.00

    saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

  • CVE-2017-6178HigMar 20, 2017
    risk 0.54cvss 7.8epss 0.00

    The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.

  • CVE-2017-6058HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.03

    Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.

  • CVE-2017-5618HigMar 20, 2017
    risk 0.51cvss 7.8epss 0.02

    GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.

  • CVE-2017-1151HigMar 20, 2017
    risk 0.53cvss 8.1epss 0.01

    IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.

  • CVE-2017-1145HigMar 20, 2017
    risk 0.56cvss 8.6epss 0.01

    IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672.

  • CVE-2017-1134HigMar 20, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.

  • CVE-2016-9165HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.01

    The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.

  • CVE-2016-5857HigMar 20, 2017
    risk 0.51cvss 7.8epss 0.00

    The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.

  • CVE-2015-8983HigMar 20, 2017
    risk 0.53cvss 8.1epss 0.01

    Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to computing a size in bytes, which triggers a heap-based buffer overflow.

  • CVE-2014-9851HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.02

    ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).

  • CVE-2014-9850HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.02

    Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).

  • CVE-2014-9849HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.02

    The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).

  • CVE-2014-9848HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.02

    Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).

  • CVE-2014-9842HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.02

    Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

  • CVE-2012-5361HigMar 20, 2017
    risk 0.51cvss 7.8epss 0.02

    Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.

  • CVE-2017-7187HigMar 20, 2017
    risk 0.51cvss 7.8epss 0.00

    The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function.

  • CVE-2017-7186HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.07

    libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.

  • CVE-2014-9938HigMar 20, 2017
    risk 0.57cvss 8.8epss 0.01

    contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

  • CVE-2017-7184HigMar 19, 2017
    risk 0.51cvss 7.8epss 0.03

    The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.

  • CVE-2017-7178HigMar 18, 2017
    risk 0.60cvss 8.8epss 0.01

    CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

  • CVE-2017-7177HigMar 18, 2017
    risk 0.49cvss 7.5epss 0.00

    Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.

  • CVE-2015-3884HigMar 17, 2017
    risk 0.66cvss 8.8epss 0.73

    Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/attachments/ or uploads/users/.

  • CVE-2015-3881HigMar 17, 2017
    risk 0.49cvss 7.5epss 0.00

    Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.

  • CVE-2014-9854HigMar 17, 2017
    risk 0.49cvss 7.5epss 0.02

    coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."

  • CVE-2014-8722HigMar 17, 2017
    risk 0.54cvss 7.5epss 0.27

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/.xml, (2) backups/users/.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.

  • CVE-2014-8701HigMar 17, 2017
    risk 0.49cvss 7.5epss 0.00

    Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.