VYPR

CVEs

37,851 total · page 684 of 758

  • CVE-2018-2368CriMar 1, 2018
    risk 0.64cvss 9.8epss 0.03

    SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.

  • CVE-2018-7561CriMar 1, 2018
    risk 0.64cvss 9.8epss 0.02

    Stack-based Buffer Overflow in httpd on Tenda AC9 devices V15.03.05.14_EN allows remote attackers to cause a denial of service or possibly have unspecified other impact.

  • CVE-2017-12627CriMar 1, 2018
    risk 0.57cvss 9.8epss 0.08

    In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

  • CVE-2018-7264CriFeb 28, 2018
    risk 0.68cvss 9.8epss 0.12

    The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process…

  • CVE-2018-7556CriFeb 28, 2018
    risk 0.59cvss 9.1epss 0.02

    LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.

  • CVE-2018-7477CriFeb 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php.

  • CVE-2018-7554CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.02

    There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

  • CVE-2018-7553CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.02

    There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

  • CVE-2018-7552CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.02

    There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

  • CVE-2018-7551CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.02

    There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

  • CVE-2018-6641CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.06

    An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This…

  • CVE-2018-6640CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.04

    A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d.

  • CVE-2018-6639CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.04

    An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.

  • CVE-2018-6638CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.04

    A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupted offset value and the second argument is a stack buffer. This is fixed in 6.9d.

  • CVE-2018-7548CriFeb 27, 2018
    risk 0.64cvss 9.8epss 0.03

    In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.

  • CVE-2017-18206CriFeb 27, 2018
    risk 0.64cvss 9.8epss 0.03

    In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

  • CVE-2016-10714CriFeb 27, 2018
    risk 0.57cvss 9.8epss 0.02

    In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.

  • CVE-2014-10072CriFeb 27, 2018
    risk 0.64cvss 9.8epss 0.03

    In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.

  • CVE-2014-10071CriFeb 27, 2018
    risk 0.64cvss 9.8epss 0.03

    In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

  • CVE-2018-6481CriFeb 27, 2018
    risk 0.68cvss 9.8epss 0.21

    A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

  • CVE-2018-1372CriFeb 27, 2018
    risk 0.64cvss 9.8epss 0.02

    IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.

  • CVE-2017-15692CriFeb 27, 2018
    risk 0.64cvss 9.8epss 0.05

    In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.

  • CVE-2018-4895CriFeb 27, 2018
    risk 0.65cvss 9.8epss 0.14

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is…

  • CVE-2018-4879CriFeb 27, 2018
    risk 0.66cvss 9.8epss 0.29

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is…

  • CVE-2018-4872CriFeb 27, 2018
    risk 0.66cvss 10.0epss 0.12

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is a security bypass vulnerability that leads to a sandbox escape. Specifically, the vulnerability…

  • CVE-2017-11634CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 9527 and reading the password field of the debugging information, e.g., nTBCS19C corresponds to a password of 123456.

  • CVE-2017-11632CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Wireless IP Camera 360 devices. A root account with a known SHA-512 password hash exists, which makes it easier for remote attackers to obtain administrative access via a TELNET session.

  • CVE-2018-7489CriFeb 26, 2018
    risk 0.58cvss 9.8epss 0.20

    FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the…

  • CVE-2018-7485CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.03

    The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

  • CVE-2017-18201CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

  • CVE-2018-7463CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2017-9426CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.03

    ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.

  • CVE-2017-18197CriFeb 24, 2018
    risk 0.57cvss 9.8epss 0.03

    In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

  • CVE-2017-14910CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.01

    In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 835, and SD 845, a buffer overread is possible if there are no…

  • CVE-2018-7442CriFeb 23, 2018
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

  • CVE-2018-7440CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.

  • CVE-2018-6859CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.

  • CVE-2014-3206CriFeb 23, 2018
    risk 0.68cvss 9.8epss 0.51

    Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.

  • CVE-2014-3205CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.03

    backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

  • CVE-2018-6489CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)

  • CVE-2018-0015CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Agent is executing. If…

  • CVE-2018-7319CriFeb 22, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.

  • CVE-2018-7318CriFeb 22, 2018
    risk 0.67cvss 9.8epss 0.09

    SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.

  • CVE-2018-7316CriFeb 22, 2018
    risk 0.67cvss 9.8epss 0.08

    Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.

  • CVE-2018-7315CriFeb 22, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.

  • CVE-2018-7314CriFeb 22, 2018
    risk 0.71cvss 9.8epss 0.58

    SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

  • CVE-2018-7312CriFeb 22, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.

  • CVE-2018-7301CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices.

  • CVE-2018-7300CriFeb 22, 2018
    risk 0.69cvss 9.8epss 0.31

    Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated…

  • CVE-2018-7297CriFeb 22, 2018
    risk 0.72cvss 9.8epss 0.64

    Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web…