CSV
14,794 results for "vulnerability" Page 118
CVE-2019-11708 CRITICAL KEV Exploit

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

Jul 23, 2019 3 affected product(s) NVD
10.0
CVSS
55.9%
EPSS
⚡ 86.8
CVE-2019-12725 CRITICAL Exploit

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

Jul 19, 2019 1 affected product(s) NVD
9.8
CVSS
89.8%
EPSS
⚡ 76.2
CVE-2019-12815 CRITICAL

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.

Jul 19, 2019 10 affected product(s) NVD
9.8
CVSS
57.6%
EPSS
⚡ 56.5
CVE-2019-0785 CRITICAL

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

Jul 15, 2019 6 affected product(s) NVD
9.8
CVSS
49.6%
EPSS
⚡ 54.1
CVE-2019-1072 CRITICAL

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

Jul 15, 2019 8 affected product(s) NVD
9.8
CVSS
12.4%
EPSS
⚡ 42.9
CVE-2019-11703 CRITICAL

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Jul 23, 2019 1 affected product(s) NVD
9.8
CVSS
10.5%
EPSS
⚡ 42.4
CVE-2019-11704 CRITICAL

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Jul 23, 2019 1 affected product(s) NVD
9.8
CVSS
10.5%
EPSS
⚡ 42.4
CVE-2019-11705 CRITICAL

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Jul 23, 2019 1 affected product(s) NVD
9.8
CVSS
9.9%
EPSS
⚡ 42.2
CVE-2019-13278 CRITICAL

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Jul 10, 2019 1 affected product(s) NVD
9.8
CVSS
8.8%
EPSS
⚡ 41.8
CVE-2019-7850 CRITICAL

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

Jul 18, 2019 1 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 40.9
CVE-2019-6823 CRITICAL

A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.

Jul 15, 2019 1 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7
CVE-2019-6824 CRITICAL

A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.

Jul 15, 2019 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.5
CVE-2019-13573 CRITICAL

A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Jul 17, 2019 1 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-7003 CRITICAL

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.

Jul 11, 2019 1 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.4
CVE-2019-13569 CRITICAL

A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Jul 19, 2019 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2019-12468 CRITICAL

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

Jul 10, 2019 2 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2019-1010022 CRITICAL

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Jul 15, 2019 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2019-13276 CRITICAL

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by providing a sufficiently long query string when POSTing to any valid cgi, txt, asp, or js file. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Jul 10, 2019 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40
CVE-2019-13279 CRITICAL

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for the setup wizard, allowing an unauthenticated user to execute arbitrary code. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Jul 10, 2019 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-13575 CRITICAL

A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

Jul 18, 2019 1 affected product(s) NVD
9.8
CVSS
2.6%
EPSS
⚡ 40