VYPR

CVEs

37,851 total · page 685 of 758

  • CVE-2018-7409CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.03

    In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.

  • CVE-2017-5250CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.

  • CVE-2017-5249CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.

  • CVE-2017-18194CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter.

  • CVE-2018-7313CriFeb 22, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

  • CVE-2018-0130CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected system. The vulnerability is due to the presence of static…

  • CVE-2018-0124CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key generation during application…

  • CVE-2018-0121CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected…

  • CVE-2015-5725CriFeb 21, 2018
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.

  • CVE-2018-1164CriFeb 21, 2018
    risk 0.64cvss 9.8epss 0.04

    This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numerous exposed CGI…

  • CVE-2018-7263CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.02

    The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

  • CVE-2018-6487CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.02

    Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.

  • CVE-2015-9254CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.01

    Datto ALTO and SIRIS devices have a default VNC password.

  • CVE-2015-2081CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.03

    Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

  • CVE-2018-7259CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.01

    The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows remote attackers to obtain sensitive information, e.g., by…

  • CVE-2018-7251CriFeb 19, 2018
    risk 0.65cvss 9.8epss 0.72

    An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

  • CVE-2017-7376CriFeb 19, 2018
    risk 0.66cvss 9.8epss 0.23

    Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

  • CVE-2017-7375CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.03

    A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack…

  • CVE-2017-17101CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Apexis APM-H803-MPC software, as used with many different models of IP Camera. An unprotected CGI method inside the web application permits an unauthenticated user to bypass the login screen and access the webcam contents including: live video stream,…

  • CVE-2016-9568CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.02

    A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.

  • CVE-2018-7247CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact.

  • CVE-2018-5475CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.04

    A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. Multiple stack-based buffer overflow vulnerabilities have been identified, which may allow remote code execution.

  • CVE-2018-5473CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.06

    An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. The SSH functions of the device are vulnerable to buffer overflow conditions that may allow a remote…

  • CVE-2018-5439CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.04

    A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.

  • CVE-2018-7226CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in vcSetXCutTextProc() in VNConsole.c in LinuxVNC and VNCommand from the LibVNC/vncterm distribution through 0.9.10. Missing sanitization of the client-specified message length may cause integer overflow or possibly have unspecified other impact via a…

  • CVE-2018-7225CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via…

  • CVE-2017-16924CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.09

    Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL,…

  • CVE-2018-6024CriFeb 18, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.

  • CVE-2018-7180CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.

  • CVE-2018-7179CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.

  • CVE-2018-7178CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.04

    SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.

  • CVE-2018-7177CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.

  • CVE-2018-6585CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.

  • CVE-2018-6584CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.04

    SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.

  • CVE-2018-6583CriFeb 17, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.

  • CVE-2018-6396CriFeb 17, 2018
    risk 0.69cvss 9.8epss 0.24

    SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.

  • CVE-2018-6394CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.

  • CVE-2018-6373CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.02

    SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.

  • CVE-2018-6372CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.

  • CVE-2018-6370CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.

  • CVE-2018-6368CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.

  • CVE-2018-6006CriFeb 17, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.

  • CVE-2018-6005CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.

  • CVE-2018-6004CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter.

  • CVE-2018-5994CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.

  • CVE-2018-5993CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request.

  • CVE-2018-5992CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request.

  • CVE-2018-5991CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.

  • CVE-2018-5990CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.

  • CVE-2018-5989CriFeb 17, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.