CVE Database

CVE-2019-16897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in the K7AVOptn.dll module to facilitate escalation of privileges via inter-process communication with a service process.

CVE-2019-14450CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.

CVE-2019-17181CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system.

CVE-2019-18189CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.

CVE-2009-3887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

ytnef has directory traversal

CVE-2012-1187CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-273

Bitlbee does not drop extra group privileges correctly in unix.c

CVE-2019-10211CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.

CVE-2019-10748CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

CVE-2019-10749CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.

CVE-2019-15678CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

CVE-2019-15679CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

CVE-2019-15683CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via network connectivity. To exploit this vulnerability authorization on server is required. These issues have been fixed in commit cea98166008301e614e0d36776bf9435a536136e.

CVE-2019-18604CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

CVE-2019-18624CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.

CVE-2019-8287CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

CVE-2009-5043CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-755

burn allows file names to escape via mishandled quotation marks

CVE-2018-21029CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)

CVE-2019-10762CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.

CVE-2019-18632CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.

CVE-2019-18633CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

CVE-2010-0748CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

CVE-2019-18425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table accesses are performed by the emulating code. Such accesses should respect the guest specified limits, unless otherwise guaranteed to fail in such a case. Without this, emulation of 32-bit guest user mode calls through call gates would allow guest user mode to install and then use descriptors of their choice, as long as the guest kernel did not itself install an LDT. (Most OSes don't install any LDT by default). 32-bit PV guest user mode can elevate its privileges to that of the guest kernel. Xen versions from at least 3.2 onwards are affected. Only 32-bit PV guest user mode can leverage this vulnerability. HVM, PVH, as well as 64-bit PV guests cannot leverage this vulnerability. Arm systems are unaffected.

CVE-2019-18364CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

CVE-2009-5041CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

overkill has buffer overflow via long player names that can corrupt data on the server machine

CVE-2019-18464CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the database.

CVE-2019-18465CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.

CVE-2013-1910CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.

CVE-2019-5151CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2012-6125CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

CVE-2019-13508CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

FreeTDS through 1.1.11 has a Buffer Overflow.

CVE-2019-13547CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.

CVE-2019-13551CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.

CVE-2013-1666CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.

CVE-2019-18226CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-294

Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.

CVE-2013-2738CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

minidlna has SQL Injection that may allow retrieval of arbitrary files

CVE-2005-3056CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

TWiki allows arbitrary shell command execution via the Include function

CVE-2019-18662CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.

CVE-2013-2259CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview

CVE-2013-2260CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-331

Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness

CVE-2019-18663CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.

CVE-2013-4409CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

CVE-2015-8980CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

CVE-2019-17212CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the current point (*packet_data_pptr) is increased correspondingly. The pointer is restricted by the size of the received buffer, as well as by the 0xFF delimiter byte. Inside each while loop, the check of the value of *packet_data_pptr is not strictly enforced. More specifically, inside a loop, *packet_data_pptr could be increased and then dereferenced without checking. Moreover, there are many other functions in the format of sn_coap_parser_****() that do not check whether the pointer is within the bounds of the allocated buffer. All of these lead to heap-based or stack-based buffer overflows, depending on how the CoAP packet buffer is allocated.

CVE-2019-17211CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory for the CoAP message from the sn_coap_hdr_s data structure. Both returned_byte_count and src_coap_msg_ptr->payload_len are of type uint16_t. When added together, the result returned_byte_count can wrap around the maximum uint16_t value. As a result, insufficient buffer space is allocated for the corresponding CoAP message.

CVE-2005-2354CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

CVE-2019-18780CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.

CVE-2011-1134CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.

CVE-2006-0062CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.

CVE-2006-3100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

termpkg 3.3 suffers from buffer overflow.

CVE-2011-1460CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-704

WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.

← PreviousPage 327 / 7034Next →