VYPR

CVEs

37,996 total · page 602 of 760

  • CVE-2019-13508CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.02

    FreeTDS through 1.1.11 has a Buffer Overflow.

  • CVE-2018-4031CriOct 31, 2019
    risk 0.65cvss 10.0epss 0.03

    An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua…

  • CVE-2012-6125CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.02

    Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

  • CVE-2010-2783CriOct 31, 2019
    risk 0.59cvss 9.1epss 0.02

    IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.

  • CVE-2010-2548CriOct 31, 2019
    risk 0.59cvss 9.1epss 0.02

    IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

  • CVE-2019-5151CriOct 31, 2019
    risk 0.65cvss 10.0epss 0.02

    An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to…

  • CVE-2019-5049CriOct 31, 2019
    risk 0.65cvss 10.0epss 0.02

    An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this…

  • CVE-2013-1910CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.

  • CVE-2019-18465CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL…

  • CVE-2019-18464CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.02

    In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the…

  • CVE-2009-5043CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    burn allows file names to escape via mishandled quotation marks

  • CVE-2009-5042CriOct 31, 2019
    risk 0.59cvss 9.1epss 0.01

    python-docutils allows insecure usage of temporary files

  • CVE-2009-5041CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    overkill has buffer overflow via long player names that can corrupt data on the server machine

  • CVE-2019-18364CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

  • CVE-2019-18425CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table…

  • CVE-2010-0748CriOct 30, 2019
    risk 0.64cvss 9.8epss 0.02

    Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

  • CVE-2019-18633CriOct 30, 2019
    risk 0.64cvss 9.8epss 0.01

    European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

  • CVE-2019-18632CriOct 30, 2019
    risk 0.57cvss 9.8epss 0.01

    European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.

  • CVE-2019-10762CriOct 30, 2019
    risk 0.57cvss 9.8epss 0.01

    columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.

  • CVE-2018-21029CriOct 30, 2019
    risk 0.64cvss 9.8epss 0.03

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability…

  • CVE-2012-0694CriOct 29, 2019
    risk 0.72cvss 9.8epss 0.67

    SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.

  • CVE-2019-8287CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.19

    TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

  • CVE-2019-18624CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.01

    Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553,…

  • CVE-2019-18604CriOct 29, 2019
    risk 0.57cvss 9.8epss 0.02

    In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

  • CVE-2019-15683CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.19

    TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via…

  • CVE-2019-15679CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.12

    TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

  • CVE-2019-15678CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.12

    TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

  • CVE-2019-10749CriOct 29, 2019
    risk 0.57cvss 9.8epss 0.01

    sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.

  • CVE-2019-10748CriOct 29, 2019
    risk 0.57cvss 9.8epss 0.01

    Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

  • CVE-2019-10211CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.

  • CVE-2012-1187CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Bitlbee does not drop extra group privileges correctly in unix.c

  • CVE-2010-3375CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.02

    qtparted has insecure library loading which may allow arbitrary code execution

  • CVE-2009-3887CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.03

    ytnef has directory traversal

  • CVE-2019-18189CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.05

    A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not…

  • CVE-2019-17181CriOct 28, 2019
    risk 0.71cvss 9.8epss 0.49

    A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system.

  • CVE-2019-14450CriOct 28, 2019
    risk 0.65cvss 9.8epss 0.10

    A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external…

  • CVE-2019-16897CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in…

  • CVE-2010-4239CriOct 28, 2019
    risk 0.65cvss 9.8epss 0.13

    Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

  • CVE-2009-4899CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.01

    pixelpost 1.7.1 has SQL injection

  • CVE-2002-2444CriOct 28, 2019
    risk 0.57cvss 9.8epss 0.02

    Snoopy before 2.0.0 has a security hole in exec cURL

  • CVE-2019-14931CriOct 28, 2019
    risk 0.71cvss 9.8epss 0.58

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user…

  • CVE-2019-14930CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the…

  • CVE-2019-14929CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak…

  • CVE-2019-14926CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial…

  • CVE-2019-16662CriOct 28, 2019
    risk 0.75cvss 9.8epss 0.98

    An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

  • CVE-2017-14742CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.

  • CVE-2019-5129CriOct 25, 2019
    risk 0.67cvss 9.8epss 0.39

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5128CriOct 25, 2019
    risk 0.66cvss 9.8epss 0.30

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5127CriOct 25, 2019
    risk 0.67cvss 9.8epss 0.45

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5114CriOct 25, 2019
    risk 0.64cvss 9.9epss 0.01

    An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,…