VYPR

CVEs

37,977 total · page 610 of 760

  • CVE-2019-15938CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.

  • CVE-2019-15937CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.

  • CVE-2019-1976CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the…

  • CVE-2019-15926CriSep 4, 2019
    risk 0.60cvss 9.1epss 0.05

    An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.

  • CVE-2019-6644CriSep 4, 2019
    risk 0.61cvss 9.4epss 0.01

    Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in…

  • CVE-2019-13976CriSep 4, 2019
    risk 0.64cvss 9.8epss 0.02

    eGain Chat 15.0.3 allows unrestricted file upload.

  • CVE-2019-10709CriSep 4, 2019
    risk 0.68cvss 9.8epss 0.12

    AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.

  • CVE-2019-15872CriSep 3, 2019
    risk 0.64cvss 9.8epss 0.02

    The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.

  • CVE-2019-15826CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.

  • CVE-2019-15825CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.

  • CVE-2019-15824CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.

  • CVE-2019-15823CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.09

    The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.

  • CVE-2019-15822CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.

  • CVE-2019-15819CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.03

    The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.

  • CVE-2019-5608CriAug 30, 2019
    risk 0.64cvss 9.8epss 0.02

    In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is…

  • CVE-2019-15806CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.01

    CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi…

  • CVE-2019-15805CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.01

    CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can…

  • CVE-2019-15717CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.

  • CVE-2019-11500CriAug 29, 2019
    risk 0.69cvss 9.8epss 0.62

    In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

  • CVE-2019-15788CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.

  • CVE-2019-15786CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.

  • CVE-2019-15785CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.03

    FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

  • CVE-2019-15784CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.

  • CVE-2019-15783CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.

  • CVE-2019-15780CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

  • CVE-2019-14943CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

  • CVE-2018-21007CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.

  • CVE-2019-13405CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.03

    A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining…

  • CVE-2019-11064CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1…

  • CVE-2019-11063CriAug 29, 2019
    risk 0.65cvss 10.0epss 0.04

    A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via…

  • CVE-2019-11061CriAug 29, 2019
    risk 0.65cvss 10.0epss 0.04

    A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10…

  • CVE-2019-9933CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have a Buffer Overflow (issue 3 of 3).

  • CVE-2019-9932CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have a Buffer Overflow (issue 2 of 3).

  • CVE-2019-9930CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have an Integer Overflow.

  • CVE-2019-15753CriAug 28, 2019
    risk 0.52cvss 9.1epss 0.03

    In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network performance and allows users to possibly view the content of…

  • CVE-2019-12643CriAug 28, 2019
    risk 0.65cvss 10.0epss 0.05

    A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that…

  • CVE-2019-10058CriAug 28, 2019
    risk 0.59cvss 9.1epss 0.01

    Various Lexmark products have Incorrect Access Control.

  • CVE-2019-15294CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the…

  • CVE-2012-6719CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    The sharebar plugin before 1.2.2 for WordPress has SQL injection.

  • CVE-2019-13486CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.

  • CVE-2019-13485CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.

  • CVE-2019-13484CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.

  • CVE-2019-13455CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.

  • CVE-2019-13452CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

  • CVE-2019-13451CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

  • CVE-2019-13273CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.

  • CVE-2019-14314CriAug 27, 2019
    risk 0.67cvss 9.8epss 0.43

    A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package…

  • CVE-2015-9352CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The wp-polls plugin before 2.72 for WordPress has SQL injection.

  • CVE-2015-9351CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.03

    The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.

  • CVE-2019-15659CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.