VYPR

CVEs

38,011 total · page 567 of 761

  • CVE-2020-0595CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-0594CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.04

    Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-14080CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.02

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by POSTing to apply_sec.cgi via the action ping_test with a sufficiently long ping_ipaddr key.

  • CVE-2020-14067CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.01

    The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

  • CVE-2020-13656CriJun 12, 2020
    risk 0.64cvss 9.8epss 0.02

    In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

  • CVE-2020-9633CriJun 12, 2020
    risk 0.64cvss 9.8epss 0.08

    Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead…

  • CVE-2020-0217CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0201CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.02

    In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0138CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User…

  • CVE-2020-4101CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.01

    "HCL Digital Experience is susceptible to Server Side Request Forgery."

  • CVE-2020-13854CriJun 11, 2020
    risk 0.64cvss 9.8epss 0.03

    Artica Pandora FMS 7.44 allows privilege escalation.

  • CVE-2020-13901CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

  • CVE-2020-12757CriJun 10, 2020
    risk 0.57cvss 9.8epss 0.02

    HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being…

  • CVE-2020-0117CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.02

    In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-7589CriJun 10, 2020
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project files from affected devices. The security vulnerability could be exploited by…

  • CVE-2020-7675CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.

  • CVE-2020-7674CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.

  • CVE-2020-7673CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution.

  • CVE-2020-6275CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions…

  • CVE-2020-6263CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for…

  • CVE-2019-4576CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.

  • CVE-2020-6265CriJun 9, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of Hardcoded Credentials.

  • CVE-2020-9850CriJun 9, 2020
    risk 0.73cvss 9.8epss 0.77

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code…

  • CVE-2020-9838CriJun 9, 2020
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5. A remote attacker may be able to cause arbitrary code execution.

  • CVE-2020-9412CriJun 9, 2020
    risk 0.65cvss 10.0epss 0.02

    The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows execution of arbitrary commands at the privilege level of the affected system following a failed file transfer. Affected…

  • CVE-2020-9411CriJun 9, 2020
    risk 0.65cvss 10.0epss 0.01

    The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file system accessible to the affected…

  • CVE-2020-13160CriJun 9, 2020
    risk 0.73cvss 9.8epss 0.81

    AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

  • CVE-2020-12800CriJun 8, 2020
    risk 0.73cvss 9.8epss 0.79

    The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

  • CVE-2020-9099CriJun 8, 2020
    risk 0.64cvss 9.8epss 0.01

    Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00;…

  • CVE-2020-8180CriJun 8, 2020
    risk 0.64cvss 9.9epss 0.02

    A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.

  • CVE-2020-6109CriJun 8, 2020
    risk 0.64cvss 9.8epss 0.05

    An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An…

  • CVE-2020-12773CriJun 8, 2020
    risk 0.62cvss 9.6epss 0.01

    A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.

  • CVE-2020-13910CriJun 7, 2020
    risk 0.59cvss 9.1epss 0.01

    Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field without any bounds check.

  • CVE-2020-13909CriJun 7, 2020
    risk 0.64cvss 9.8epss 0.01

    The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix.

  • CVE-2020-10071CriJun 5, 2020
    risk 0.52cvss 9.0epss 0.03

    The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.

  • CVE-2020-10070CriJun 5, 2020
    risk 0.59cvss 9.0epss 0.03

    In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.

  • CVE-2020-10062CriJun 5, 2020
    risk 0.59cvss 9.0epss 0.03

    An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.

  • CVE-2020-4450CriJun 5, 2020
    risk 0.66cvss 9.8epss 0.34

    IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.

  • CVE-2020-4448CriJun 5, 2020
    risk 0.65cvss 9.8epss 0.12

    IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.

  • CVE-2020-11975CriJun 5, 2020
    risk 0.66cvss 9.8epss 0.31

    Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

  • CVE-2020-13841CriJun 5, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended access restrictions. The LG ID is LVE-SMP-200009 (June 2020).

  • CVE-2020-13840CriJun 5, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020).

  • CVE-2020-13839CriJun 5, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).

  • CVE-2020-13768CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.

  • CVE-2020-13835CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).

  • CVE-2020-13833CriJun 4, 2020
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).

  • CVE-2020-13832CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine Trustlet allows arbitrary code execution because of memory disclosure, The Samsung IDs are SVE-2020-17117, SVE-2020-17118, SVE-2020-17119, and SVE-2020-17161…

  • CVE-2020-13831CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020).

  • CVE-2019-20830CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used.

  • CVE-2019-20827CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It allows stack consumption because of interaction between ICC-Based color space and Alternate color space.