VYPR

CVEs

37,902 total · page 669 of 759

  • CVE-2016-9080CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.

  • CVE-2016-9075CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects…

  • CVE-2016-9063CriJun 11, 2018
    risk 0.57cvss 9.8epss 0.05

    An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

  • CVE-2016-5297CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.04

    An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

  • CVE-2016-5290CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.03

    Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox…

  • CVE-2016-5289CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.

  • CVE-2016-5287CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

  • CVE-2018-6512CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe-razor-server prior to 1.9.0.0.

  • CVE-2017-3208CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.04

    The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive…

  • CVE-2017-3207CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.08

    The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to…

  • CVE-2017-3206CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.04

    The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data…

  • CVE-2017-3202CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.08

    The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The ability to exploit this…

  • CVE-2018-12092CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

  • CVE-2018-0225CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Security Advisory 2089 issue.

  • CVE-2018-4229CriJun 8, 2018
    risk 0.65cvss 10.0epss 0.02

    An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Grand Central Dispatch" component. It allows attackers to bypass a sandbox protection mechanism by leveraging the misparsing of entitlement plists.

  • CVE-2018-12065CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.03

    A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.

  • CVE-2018-12064CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.

  • CVE-2018-10088CriJun 8, 2018
    risk 0.70cvss 9.8epss 0.40

    Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

  • CVE-2018-12055CriJun 8, 2018
    risk 0.67cvss 9.8epss 0.03

    Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.

  • CVE-2018-12052CriJun 8, 2018
    risk 0.67cvss 9.8epss 0.05

    SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.

  • CVE-2018-12051CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.03

    Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.

  • CVE-2018-9246CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.03

    The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore()…

  • CVE-2018-12049CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.05

    A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps…

  • CVE-2018-12048CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.05

    A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the…

  • CVE-2018-12045CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.

  • CVE-2018-11229CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.06

    Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).

  • CVE-2018-11228CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.07

    Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).

  • CVE-2018-12039CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.05

    joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring.

  • CVE-2018-12031CriJun 7, 2018
    risk 0.65cvss 9.8epss 0.20

    Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action.

  • CVE-2018-0321CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An…

  • CVE-2018-0320CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation on user-supplied input in SQL queries. An attacker…

  • CVE-2018-0319CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery…

  • CVE-2018-0318CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password reset request. An…

  • CVE-2018-0315CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.08

    A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of…

  • CVE-2018-3739CriJun 7, 2018
    risk 0.52cvss 9.1epss 0.02

    https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

  • CVE-2017-16226CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.04

    The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.

  • CVE-2017-16151CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.03

    Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the…

  • CVE-2017-16128CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.01

    The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.

  • CVE-2017-16127CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.01

    The module pandora-doomsday infects other modules. It's since been unpublished from the registry.

  • CVE-2017-16100CriJun 7, 2018
    risk 0.57cvss 9.8epss 0.05

    dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

  • CVE-2017-16088CriJun 7, 2018
    risk 0.65cvss 10.0epss 0.03

    The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.

  • CVE-2017-16082CriJun 7, 2018
    risk 0.65cvss 9.8epss 0.11

    A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a…

  • CVE-2018-7510CriJun 6, 2018
    risk 0.64cvss 9.8epss 0.01

    In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.

  • CVE-2017-7933CriJun 6, 2018
    risk 0.64cvss 9.8epss 0.02

    In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.

  • CVE-2017-7931CriJun 6, 2018
    risk 0.64cvss 9.8epss 0.03

    In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.

  • CVE-2018-11808CriJun 6, 2018
    risk 0.60cvss 9.1epss 0.06

    Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by…

  • CVE-2018-11586CriJun 5, 2018
    risk 0.68cvss 9.8epss 0.15

    XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

  • CVE-2017-7637CriJun 5, 2018
    risk 0.64cvss 9.8epss 0.03

    QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.

  • CVE-2016-9488CriJun 5, 2018
    risk 0.67cvss 9.8epss 0.05

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users'…

  • CVE-2018-11743CriJun 5, 2018
    risk 0.64cvss 9.8epss 0.02

    The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.