CSV
14,794 results for "vulnerability" Page 133
CVE-2019-18935 CRITICAL KEV Exploit

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

Dec 11, 2019 1 affected product(s) NVD
9.8
CVSS
99.7%
EPSS
⚡ 99.1
CVE-2019-7195 CRITICAL KEV Exploit

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Dec 5, 2019 4 affected product(s) NVD
9.8
CVSS
89.7%
EPSS
⚡ 96.1
CVE-2019-7192 CRITICAL KEV Exploit

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Dec 5, 2019 4 affected product(s) NVD
9.8
CVSS
88.2%
EPSS
⚡ 95.7
CVE-2019-7194 CRITICAL KEV Exploit

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Dec 5, 2019 4 affected product(s) NVD
9.8
CVSS
83.1%
EPSS
⚡ 94.1
CVE-2019-7193 CRITICAL KEV Exploit

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Dec 5, 2019 16 affected product(s) NVD
9.8
CVSS
14.4%
EPSS
⚡ 73.5
CVE-2019-5096 CRITICAL

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.

Dec 3, 2019 3 affected product(s) NVD
9.8
CVSS
67.0%
EPSS
⚡ 59.3
CVE-2019-12518 CRITICAL

Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

Dec 2, 2019 2 affected product(s) NVD
9.8
CVSS
50.7%
EPSS
⚡ 54.4
CVE-2019-18283 CRITICAL

A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one of its functions. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Dec 12, 2019 3 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2019-18289 CRITICAL

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18293, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2019-18293 CRITICAL

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2019-18295 CRITICAL

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18293, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2019-18296 CRITICAL

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18293, and CVE-2019-18295. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2019-19230 CRITICAL

An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

Dec 9, 2019 1 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2019-18671 CRITICAL

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.

Dec 6, 2019 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2019-5085 CRITICAL

An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a packet to trigger this vulnerability.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2019-16246 CRITICAL

Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2019-18190 CRITICAL

Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.

Dec 9, 2019 4 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-5093 CRITICAL

An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a packet to trigger this vulnerability.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
2.5%
EPSS
⚡ 40
CVE-2019-15931 CRITICAL

Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-18313 CRITICAL

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could gain remote code execution by sending specifically crafted objects to one of the RPC services. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Dec 12, 2019 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40