CSV
14,794 results for "vulnerability" Page 119
CVE-2019-11708 CRITICAL KEV Exploit

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

Jul 23, 2019 3 affected product(s) NVD
10.0
CVSS
55.9%
EPSS
⚡ 86.8
CVE-2019-12256 CRITICAL

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.

Aug 9, 2019 31 affected product(s) NVD
9.8
CVSS
26.6%
EPSS
⚡ 47.2
CVE-2019-11703 CRITICAL

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Jul 23, 2019 1 affected product(s) NVD
9.8
CVSS
10.5%
EPSS
⚡ 42.4
CVE-2019-11704 CRITICAL

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Jul 23, 2019 1 affected product(s) NVD
9.8
CVSS
10.5%
EPSS
⚡ 42.4
CVE-2019-11705 CRITICAL

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7.1.

Jul 23, 2019 1 affected product(s) NVD
9.8
CVSS
9.9%
EPSS
⚡ 42.2
CVE-2019-5684 CRITICAL

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.

Aug 6, 2019 1 affected product(s) NVD
10.0
CVSS
5.4%
EPSS
⚡ 41.6
CVE-2019-1912 CRITICAL

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to modify the configuration of an affected device or to inject a reverse shell. This vulnerability affects Cisco Small Business 220 Series Smart Switches running firmware versions prior to 1.1.4.4 with the web management interface enabled. The web management interface is enabled via both HTTP and HTTPS by default.

Aug 7, 2019 11 affected product(s) NVD
9.1
CVSS
17.0%
EPSS
⚡ 41.5
CVE-2019-14277 CRITICAL

Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vulnerability because “All attacks that use external entities are blocked (no external DTD or file inclusions, no SSRF). The impact on confidentiality, integrity and availability is not proved on any version.

Jul 26, 2019 5 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2018-20961 CRITICAL

In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.

Aug 7, 2019 4 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2019-14537 CRITICAL

YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

Aug 7, 2019 1 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2019-5685 CRITICAL

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access to a shader local temporary array, which may lead to denial of service or code execution.

Aug 6, 2019 1 affected product(s) NVD
9.8
CVSS
5.0%
EPSS
⚡ 40.7
CVE-2019-14313 CRITICAL

A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.

Jul 30, 2019 1 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.5
CVE-2019-13571 CRITICAL

A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Jul 29, 2019 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2019-13569 CRITICAL

A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Jul 19, 2019 1 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2019-1971 CRITICAL

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

Aug 8, 2019 1 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2019-14695 CRITICAL

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.

Aug 6, 2019 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-11693 CRITICAL

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

Jul 23, 2019 3 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9
CVE-2019-11709 CRITICAL

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Jul 23, 2019 7 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9
CVE-2019-9141 CRITICAL

ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for remote code execution.

Aug 2, 2019 1 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9
CVE-2019-1895 CRITICAL

A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.

Aug 7, 2019 1 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9