VYPR

CVEs

38,010 total · page 570 of 761

  • CVE-2020-0103CriMay 14, 2020
    risk 0.64cvss 9.8epss 0.02

    In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-12874CriMay 14, 2020
    risk 0.64cvss 9.8epss 0.01

    Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.

  • CVE-2020-11973CriMay 14, 2020
    risk 0.64cvss 9.8epss 0.07

    Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

  • CVE-2020-11972CriMay 14, 2020
    risk 0.64cvss 9.8epss 0.06

    Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

  • CVE-2019-17562CriMay 14, 2020
    risk 0.57cvss 9.8epss 0.03

    A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell…

  • CVE-2019-13022CriMay 14, 2020
    risk 0.64cvss 9.8epss 0.01

    Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plaintext into the 'encrypted' password that is then stored within the database. These…

  • CVE-2020-2018CriMay 13, 2020
    risk 0.59cvss 9.0epss 0.01

    An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firewalls. An attacker requires some knowledge of managed firewalls to exploit this…

  • CVE-2020-12832CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.07

    WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

  • CVE-2020-9502CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

  • CVE-2020-7454CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.03

    In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was…

  • CVE-2019-15880CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.02

    In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.

  • CVE-2020-12763CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.03

    TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This may result in remote code execution or denial of service. The issue is in the binary rtspd (in /sbin) when parsing a long…

  • CVE-2020-10654CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.

  • CVE-2020-11057CriMay 12, 2020
    risk 0.65cvss 9.9epss 0.02

    In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.

  • CVE-2020-6242CriMay 12, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate,…

  • CVE-2020-12823CriMay 12, 2020
    risk 0.64cvss 9.8epss 0.05

    OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.

  • CVE-2020-1939CriMay 12, 2020
    risk 0.64cvss 9.8epss 0.03

    The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the optional apps…

  • CVE-2020-8159CriMay 12, 2020
    risk 0.57cvss 9.8epss 0.05

    There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.

  • CVE-2020-10022CriMay 11, 2020
    risk 0.52cvss 9.0epss 0.02

    A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the worst case. See NCC-NCC-016 This issue affects: zephyrproject-rtos zephyr…

  • CVE-2018-1285CriMay 11, 2020
    risk 0.65cvss 9.8epss 0.17

    Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

  • CVE-2020-12753CriMay 11, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May 2020).

  • CVE-2020-12747CriMay 11, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. The Bootloader has a heap-based buffer overflow because of the mishandling of specific commands. The Samsung IDs are SVE-2020-16981, SVE-2020-16991 (May 2020).

  • CVE-2020-12746CriMay 11, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets) software. Attackers can bypass the Secure Bootloader protection mechanism via a heap-based buffer overflow to execute arbitrary code. The Samsung ID is SVE-2020-16712 (May 2020).

  • CVE-2020-12743CriMay 11, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allows arbitrary PHP file inclusion via a…

  • CVE-2020-12766CriMay 9, 2020
    risk 0.64cvss 9.8epss 0.01

    Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter.

  • CVE-2020-12761CriMay 9, 2020
    risk 0.59cvss 9.1epss 0.02

    modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.

  • CVE-2020-12637CriMay 9, 2020
    risk 0.64cvss 9.8epss 0.01

    Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.

  • CVE-2020-11532CriMay 8, 2020
    risk 0.73cvss 9.8epss 0.77

    Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

  • CVE-2020-11530CriMay 8, 2020
    risk 0.74cvss 9.8epss 0.96

    A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

  • CVE-2020-11006CriMay 8, 2020
    risk 0.59cvss 9.1epss 0.01

    In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.

  • CVE-2020-12740CriMay 8, 2020
    risk 0.59cvss 9.1epss 0.02

    tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

  • CVE-2020-12022CriMay 8, 2020
    risk 0.64cvss 9.8epss 0.02

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.

  • CVE-2020-12006CriMay 8, 2020
    risk 0.64cvss 9.8epss 0.04

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

  • CVE-2020-12002CriMay 8, 2020
    risk 0.64cvss 9.8epss 0.09

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

  • CVE-2020-10638CriMay 8, 2020
    risk 0.64cvss 9.8epss 0.07

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

  • CVE-2020-12735CriMay 8, 2020
    risk 0.64cvss 9.8epss 0.02

    reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

  • CVE-2020-12720CriMay 8, 2020
    risk 0.74cvss 9.8epss 0.89

    vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

  • CVE-2020-11050CriMay 7, 2020
    risk 0.59cvss 9.0epss 0.01

    In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

  • CVE-2020-10794CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.01

    Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.

  • CVE-2020-10176CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.02

    ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.

  • CVE-2020-4429CriMay 7, 2020
    risk 0.72cvss 9.8epss 0.72

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.

  • CVE-2020-4428CriKEVMay 7, 2020
    risk 0.79cvss 9.1epss 0.62

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

  • CVE-2020-4427CriKEVMay 7, 2020
    risk 0.84cvss 9.8epss 0.70

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the…

  • CVE-2020-7805CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.

  • CVE-2020-7646CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.02

    curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

  • CVE-2020-11431CriMay 7, 2020
    risk 0.59cvss 9.1epss 0.02

    The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.

  • CVE-2019-18869CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.01

    Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.

  • CVE-2019-18868CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.01

    Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.

  • CVE-2020-8899CriMay 6, 2020
    risk 0.64cvss 9.8epss 0.06

    There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram…

  • CVE-2020-3318CriMay 6, 2020
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the…