VYPR

CVEs

37,996 total · page 601 of 760

  • CVE-2019-2283CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2019-2258CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in…

  • CVE-2019-2249CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9205,…

  • CVE-2019-10565CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-10542CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-10541CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…

  • CVE-2019-10534CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…

  • CVE-2019-10533CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206,…

  • CVE-2019-10531CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439

  • CVE-2019-10528CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables…

  • CVE-2019-10522CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607,…

  • CVE-2019-10505CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2011-4628CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.

  • CVE-2010-2446CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.03

    Rbot Reaction plugin allows command execution

  • CVE-2019-12918CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].

  • CVE-2016-4401CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.

  • CVE-2007-0899CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

  • CVE-2019-18784CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.

  • CVE-2006-4243CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.

  • CVE-2006-3100CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    termpkg 3.3 suffers from buffer overflow.

  • CVE-2006-0062CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.01

    xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.

  • CVE-2006-0061CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.

  • CVE-2019-8158CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.01

    An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted…

  • CVE-2019-8149CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.02

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.

  • CVE-2019-8144CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.02

    A remote code execution vulnerability exists in Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can insert a malicious payload through PageBuilder template methods.

  • CVE-2019-8136CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.01

    An insecure component vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Magento 2 codebase leveraged outdated versions of HTTP specification abstraction implemented in symphony component.

  • CVE-2019-8135CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.02

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.

  • CVE-2019-8121CriNov 5, 2019
    risk 0.57cvss 9.8epss 0.01

    An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.

  • CVE-2011-1460CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.01

    WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.

  • CVE-2011-1134CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.03

    Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.

  • CVE-2019-18780CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.06

    An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance…

  • CVE-2005-2354CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

  • CVE-2019-17211CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.03

    An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory for the CoAP message from the sn_coap_hdr_s data structure. Both returned_byte_count and…

  • CVE-2019-17212CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.03

    Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the…

  • CVE-2015-8980CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.07

    The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

  • CVE-2013-4409CriNov 4, 2019
    risk 0.57cvss 9.8epss 0.04

    An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

  • CVE-2019-18663CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.

  • CVE-2013-2260CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness

  • CVE-2013-2259CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.04

    Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview

  • CVE-2013-4103CriNov 4, 2019
    risk 0.67cvss 9.8epss 0.07

    Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

  • CVE-2013-4102CriNov 4, 2019
    risk 0.59cvss 9.1epss 0.02

    Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness

  • CVE-2019-18662CriNov 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query.…

  • CVE-2013-1666CriNov 1, 2019
    risk 0.64cvss 9.8epss 0.02

    Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.

  • CVE-2011-3923CriNov 1, 2019
    risk 0.74cvss 9.8epss 0.89

    Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

  • CVE-2013-2739CriNov 1, 2019
    risk 0.67cvss 9.8epss 0.05

    MiniDLNA has heap-based buffer overflow

  • CVE-2005-3056CriNov 1, 2019
    risk 0.64cvss 9.8epss 0.03

    TWiki allows arbitrary shell command execution via the Include function

  • CVE-2013-2738CriNov 1, 2019
    risk 0.64cvss 9.8epss 0.02

    minidlna has SQL Injection that may allow retrieval of arbitrary files

  • CVE-2019-18226CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.

  • CVE-2019-13551CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.05

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an…

  • CVE-2019-13547CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.