VYPR

CVEs

37,872 total · page 679 of 758

  • CVE-2017-14469CriApr 5, 2018
    risk 0.68cvss 10.0epss 0.38

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14468CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.38

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14467CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14466CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.38

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14465CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.35

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14464CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.38

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14463CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.39

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14462CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.35

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-2869CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.03

    An exploitable code execution vulnerability exists in the OpenProducer functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in code execution. An attacker can send a malicious packet to trigger this…

  • CVE-2017-2868CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.03

    An exploitable code execution vulnerability exists in the NewProducerStream functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in code execution. An attacker can send a malicious packet to trigger this…

  • CVE-2017-2867CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.02

    An exploitable code execution vulnerability exists in the SavePatientMontage functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in code execution. An attacker can a malicious packet to trigger this…

  • CVE-2017-2853CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.03

    An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in arbitrary command execution. An attacker can send a malicious…

  • CVE-2014-3413CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.02

    The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access.

  • CVE-2018-1282CriApr 5, 2018
    risk 0.60cvss 9.1epss 0.05

    This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.

  • CVE-2018-9309CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

  • CVE-2018-1002150CriApr 4, 2018
    risk 0.59cvss 9.1epss 0.02

    Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.

  • CVE-2018-9285CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.04

    Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices…

  • CVE-2018-9284CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.05

    authentication.cgi on D-Link DIR-868L devices with Singapore StarHub firmware before v1.21SHCb03 allows remote attackers to execute arbitrary code.

  • CVE-2018-9126CriApr 4, 2018
    risk 0.71cvss 9.8epss 0.49

    The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.

  • CVE-2018-9035CriApr 4, 2018
    risk 0.66cvss 9.6epss 0.07

    CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.

  • CVE-2018-1469CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.03

    IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.

  • CVE-2016-8488CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

  • CVE-2016-8487CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823724.

  • CVE-2016-8484CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823575.

  • CVE-2016-10299CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32577244.

  • CVE-2016-10298CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393252.

  • CVE-2016-10233CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.

  • CVE-2016-10230CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.03

    A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.

  • CVE-2015-9014CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393750.

  • CVE-2015-9013CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393251.

  • CVE-2015-9012CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384691.

  • CVE-2015-9011CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714882.

  • CVE-2015-9010CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393101.

  • CVE-2015-9009CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393600.

  • CVE-2015-9008CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384689.

  • CVE-2014-9959CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36383694.

  • CVE-2014-9958CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384774.

  • CVE-2014-9957CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36387564.

  • CVE-2014-9956CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36389611.

  • CVE-2014-9955CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384686.

  • CVE-2014-9954CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36388559.

  • CVE-2014-9953CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.01

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714770.

  • CVE-2018-6873CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

  • CVE-2017-13272CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…

  • CVE-2017-13266CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…

  • CVE-2017-13292CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:…

  • CVE-2017-13285CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed…

  • CVE-2017-13284CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2017-13283CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.…

  • CVE-2017-13282CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.…