VYPR

CVEs

37,965 total · page 616 of 760

  • CVE-2019-5685CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.05

    NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access to a shader local temporary array, which may lead to denial of service or code execution.

  • CVE-2019-5684CriAug 6, 2019
    risk 0.65cvss 10.0epss 0.05

    NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.

  • CVE-2019-13143CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.03

    An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to…

  • CVE-2019-14697CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.03

    musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.

  • CVE-2019-14695CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers…

  • CVE-2019-5502CriAug 5, 2019
    risk 0.59cvss 9.1epss 0.01

    SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data.

  • CVE-2019-14348CriAug 5, 2019
    risk 0.68cvss 9.8epss 0.21

    The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

  • CVE-2019-14551CriAug 3, 2019
    risk 0.64cvss 9.8epss 0.01

    Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers download and execution of code within a ZIP archive.

  • CVE-2019-14544CriAug 2, 2019
    risk 0.57cvss 9.8epss 0.02

    routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

  • CVE-2019-7163CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.02

    The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.

  • CVE-2019-9141CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.02

    ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for remote code execution.

  • CVE-2019-14532CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.

  • CVE-2019-14531CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.

  • CVE-2019-14529CriAug 2, 2019
    risk 0.66cvss 9.8epss 0.28

    OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.

  • CVE-2019-10938CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All…

  • CVE-2016-10817CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

  • CVE-2019-14495CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.

  • CVE-2016-10824CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

  • CVE-2019-13572CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.

  • CVE-2016-10858CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).

  • CVE-2016-10855CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.03

    cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

  • CVE-2018-20887CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.01

    cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

  • CVE-2019-14463CriJul 31, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.

  • CVE-2019-14462CriJul 31, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.

  • CVE-2019-12797CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.01

    A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.

  • CVE-2019-14204CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.

  • CVE-2019-14203CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply.

  • CVE-2019-14202CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.

  • CVE-2019-14201CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.

  • CVE-2019-14200CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply.

  • CVE-2019-14199CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.

  • CVE-2019-14198CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case.

  • CVE-2019-14197CriJul 31, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply.

  • CVE-2019-14196CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply.

  • CVE-2019-14195CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.

  • CVE-2019-14194CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.

  • CVE-2019-14193CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length.

  • CVE-2019-14192CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.

  • CVE-2019-5454CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.

  • CVE-2019-13026CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.01

    OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.

  • CVE-2018-20871CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).

  • CVE-2019-14313CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.

  • CVE-2019-11202CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher…

  • CVE-2018-20863CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

  • CVE-2019-13635CriJul 30, 2019
    risk 0.63cvss 9.1epss 0.44

    The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.

  • CVE-2015-9290CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.03

    In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.

  • CVE-2019-14431CriJul 29, 2019
    risk 0.64cvss 9.8epss 0.04

    In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server…

  • CVE-2018-11773CriJul 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that…

  • CVE-2019-14271CriJul 29, 2019
    risk 0.58cvss 9.8epss 0.19

    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

  • CVE-2019-13571CriJul 29, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.