VYPR

CVEs

38,011 total · page 566 of 761

  • CVE-2020-14931CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.03

    A stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) 1.3a might allow remote WHOIS servers to execute arbitrary code via a long line in a response that is mishandled by nic_format_buff.

  • CVE-2017-18920CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.

  • CVE-2017-18915CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.

  • CVE-2017-18908CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.

  • CVE-2016-11074CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.

  • CVE-2016-11064CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

  • CVE-2017-18912CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.

  • CVE-2017-18911CriJun 19, 2020
    risk 0.52cvss 9.1epss 0.01

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.

  • CVE-2017-18900CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.

  • CVE-2017-18888CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.

  • CVE-2017-18885CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.

  • CVE-2017-18883CriJun 19, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.

  • CVE-2020-8165CriJun 19, 2020
    risk 0.67cvss 9.8epss 0.46

    A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

  • CVE-2018-21251CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.

  • CVE-2019-20856CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.

  • CVE-2019-20853CriJun 19, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem.

  • CVE-2019-20851CriJun 19, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

  • CVE-2020-12886CriJun 18, 2020
    risk 0.59cvss 9.1epss 0.01

    A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses the CoAP packet header starting from the message token. The length of the token in…

  • CVE-2020-12884CriJun 18, 2020
    risk 0.59cvss 9.1epss 0.01

    A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse_multiple_options() parses CoAP options that may occur multiple consecutive times in a single…

  • CVE-2020-12883CriJun 18, 2020
    risk 0.59cvss 9.1epss 0.02

    Buffer over-reads were discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the…

  • CVE-2020-11503CriJun 18, 2020
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

  • CVE-2020-13640CriJun 18, 2020
    risk 0.65cvss 9.8epss 0.13

    A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

  • CVE-2017-9104CriJun 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.

  • CVE-2017-9103CriJun 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into…

  • CVE-2017-9109CriJun 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME…

  • CVE-2020-11901CriJun 17, 2020
    risk 0.60cvss 9.0epss 0.21

    The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.

  • CVE-2020-11898CriJun 17, 2020
    risk 0.61cvss 9.1epss 0.19

    The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.

  • CVE-2020-11897CriJun 17, 2020
    risk 0.66cvss 10.0epss 0.09

    The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.

  • CVE-2020-11896CriJun 17, 2020
    risk 0.68cvss 10.0epss 0.37

    The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.

  • CVE-2020-7512CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.01

    A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to exploit the component.

  • CVE-2020-7508CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.01

    A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.

  • CVE-2020-7500CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious…

  • CVE-2020-7498CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is considered a vulnerability, which could cause unauthorized…

  • CVE-2020-7497CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer…

  • CVE-2020-9296CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.02

    Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message…

  • CVE-2020-0235CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.00

    In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct…

  • CVE-2020-0232CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.00

    Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the session object and delete it using abc_pcie_dma_user_xfer_clean. If this happens,…

  • CVE-2020-0223CriJun 16, 2020
    risk 0.64cvss 9.8epss 0.00

    This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450

  • CVE-2020-5754CriJun 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

  • CVE-2020-12019CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.02

    WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-12001CriJun 15, 2020
    risk 0.65cvss 9.8epss 0.12

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx…

  • CVE-2020-11969CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.04

    If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1.0 - 7.1.2, Apache…

  • CVE-2020-14034CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

  • CVE-2020-14033CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.

  • CVE-2018-21246CriJun 15, 2020
    risk 0.57cvss 9.8epss 0.03

    Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

  • CVE-2018-21245CriJun 15, 2020
    risk 0.59cvss 9.1epss 0.01

    Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

  • CVE-2020-14054CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.01

    SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page.

  • CVE-2020-14011CriJun 15, 2020
    risk 0.69cvss 9.8epss 0.29

    Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled Deployments features.

  • CVE-2020-4469CriJun 15, 2020
    risk 0.65cvss 9.8epss 0.13

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to…

  • CVE-2020-4216CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.02

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066.