VYPR

CVEs

37,995 total · page 607 of 760

  • CVE-2019-16676CriSep 30, 2019
    risk 0.57cvss 9.8epss 0.03

    Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.

  • CVE-2019-16941CriSep 28, 2019
    risk 0.57cvss 9.8epss 0.05

    NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoR…

  • CVE-2019-3766CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.02

    Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targeted accounts.

  • CVE-2019-16928CriKEVSep 27, 2019
    risk 0.79cvss 9.8epss 0.42

    Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

  • CVE-2019-9459CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9365CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9301CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663384

  • CVE-2019-11734CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects…

  • CVE-2019-11733CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering…

  • CVE-2019-8074CriSep 27, 2019
    risk 0.65cvss 9.8epss 0.19

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.

  • CVE-2019-8073CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.08

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

  • CVE-2019-16920CriKEVSep 27, 2019
    risk 0.84cvss 9.8epss 1.00

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who…

  • CVE-2019-16915CriSep 26, 2019
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

  • CVE-2019-16894CriSep 26, 2019
    risk 0.67cvss 9.8epss 0.03

    download.php in inoERP 4.15 allows SQL injection through insecure deserialization.

  • CVE-2019-16755CriSep 26, 2019
    risk 0.64cvss 9.8epss 0.03

    BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions:…

  • CVE-2019-10082CriSep 26, 2019
    risk 0.60cvss 9.1epss 0.17

    In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.

  • CVE-2015-9435CriSep 26, 2019
    risk 0.64cvss 9.8epss 0.02

    The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.

  • CVE-2019-15941CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access…

  • CVE-2019-15069CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.01

    An unsafe authentication interface was discovered in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 . An attacker can bypass authentication without modifying device file and gain web page management privilege.

  • CVE-2019-15068CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.

  • CVE-2019-15067CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware version ?<= SECFS-2013-10-16-13:42:58-629c30ee-60c68be6. An attacker can bypass authentication and gain privilege by modifying the login page.

  • CVE-2019-12204CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.01

    In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticated admin access.

  • CVE-2019-16881CriSep 25, 2019
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in the portaudio-rs crate through 0.3.1 for Rust. There is a use-after-free with resultant arbitrary code execution because of a lack of unwind safety in stream_callback and stream_finished_callback.

  • CVE-2019-16880CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method.

  • CVE-2019-16194CriSep 25, 2019
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.

  • CVE-2019-10418CriSep 25, 2019
    risk 0.64cvss 9.9epss 0.01

    Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

  • CVE-2019-10417CriSep 25, 2019
    risk 0.64cvss 9.9epss 0.01

    Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

  • CVE-2019-16868CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.03

    emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.

  • CVE-2019-16759CriKEVSep 24, 2019
    risk 0.87cvss 9.8epss 1.00

    vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

  • CVE-2019-16724CriSep 24, 2019
    risk 0.72cvss 9.8epss 0.72

    File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.

  • CVE-2019-5505CriSep 24, 2019
    risk 0.64cvss 9.8epss 0.01

    ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.

  • CVE-2019-5504CriSep 24, 2019
    risk 0.64cvss 9.8epss 0.02

    ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.

  • CVE-2019-16411CriSep 24, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a memory region that is not allocated. There is a check for o->len < 5 (corresponding to 2 bytes of…

  • CVE-2019-16410CriSep 24, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a lack of header_len checking.

  • CVE-2019-15699CriSep 24, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match…

  • CVE-2019-16383CriSep 24, 2019
    risk 0.65cvss 9.4epss 0.05

    MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or…

  • CVE-2019-16748CriSep 24, 2019
    risk 0.64cvss 9.8epss 0.01

    In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignature_ex in wolfcrypt/src/asn.c.

  • CVE-2019-16746CriSep 24, 2019
    risk 0.65cvss 9.8epss 0.13

    An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.

  • CVE-2019-16377CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.03

    The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.

  • CVE-2019-3416CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.01

    All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.

  • CVE-2019-16722CriSep 23, 2019
    risk 0.64cvss 9.8epss 0.03

    ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.

  • CVE-2019-16705CriSep 23, 2019
    risk 0.59cvss 9.1epss 0.02

    Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.

  • CVE-2019-16702CriSep 23, 2019
    risk 0.68cvss 9.8epss 0.11

    Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI.

  • CVE-2019-16696CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.02

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.

  • CVE-2019-16695CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.02

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.

  • CVE-2019-16694CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.02

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

  • CVE-2019-16693CriSep 22, 2019
    risk 0.67cvss 9.8epss 0.04

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

  • CVE-2019-16692CriSep 22, 2019
    risk 0.68cvss 9.8epss 0.10

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

  • CVE-2018-21018CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.03

    Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

  • CVE-2019-16656CriSep 21, 2019
    risk 0.64cvss 9.8epss 0.01

    joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.