CSV
14,794 results for "vulnerability" Page 129
CVE-2019-14931 CRITICAL

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

Oct 28, 2019 2 affected product(s) NVD
9.8
CVSS
58.1%
EPSS
⚡ 56.6
CVE-2019-18370 CRITICAL

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

Oct 23, 2019 1 affected product(s) NVD
9.8
CVSS
40.3%
EPSS
⚡ 51.3
CVE-2019-18394 CRITICAL

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

Oct 24, 2019 1 affected product(s) NVD
9.8
CVSS
32.3%
EPSS
⚡ 48.9
CVE-2019-8196 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
22.9%
EPSS
⚡ 46.1
CVE-2019-15683 CRITICAL

TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via network connectivity. To exploit this vulnerability authorization on server is required. These issues have been fixed in commit cea98166008301e614e0d36776bf9435a536136e.

Oct 29, 2019 1 affected product(s) NVD
9.8
CVSS
19.4%
EPSS
⚡ 45
CVE-2019-8197 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
16.8%
EPSS
⚡ 44.3
CVE-2019-14450 CRITICAL

A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.

Oct 28, 2019 1 affected product(s) NVD
9.8
CVSS
10.4%
EPSS
⚡ 42.3
CVE-2019-18780 CRITICAL

An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.

Nov 5, 2019 9 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2019-8088 CRITICAL

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Oct 25, 2019 4 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 40.9
CVE-2018-4031 CRITICAL

An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua statement without prior sanitization, which results in arbitrary Lua script execution in the kernel. An attacker could send an HTTP request to exploit this vulnerability.

Oct 31, 2019 1 affected product(s) NVD
10.0
CVSS
2.7%
EPSS
⚡ 40.8
CVE-2019-5151 CRITICAL

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

Oct 31, 2019 1 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2019-18189 CRITICAL

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.

Oct 28, 2019 7 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.6
CVE-2019-5049 CRITICAL

An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

Oct 31, 2019 6 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2019-8199 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2019-8200 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2019-8205 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2019-8211 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2019-8212 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2019-8213 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2019-8214 CRITICAL

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Oct 17, 2019 6 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4