CSV
14,784 results for "vulnerability" Page 143
CVE-2020-1938 CRITICAL KEV Exploit

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.

Feb 24, 2020 38 affected product(s) NVD
9.8
CVSS
99.3%
EPSS
⚡ 99
CVE-2020-8794 CRITICAL Exploit

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

Feb 25, 2020 7 affected product(s) NVD
9.8
CVSS
88.9%
EPSS
⚡ 75.9
CVE-2020-8012 CRITICAL Exploit

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

Feb 18, 2020 3 affected product(s) NVD
9.8
CVSS
77.4%
EPSS
⚡ 72.4
CVE-2020-4211 CRITICAL Exploit

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
71.1%
EPSS
⚡ 70.5
CVE-2013-4211 CRITICAL Exploit

A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code

Feb 14, 2020 1 affected product(s) NVD
9.8
CVSS
70.7%
EPSS
⚡ 70.4
CVE-2020-8010 CRITICAL

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

Feb 18, 2020 3 affected product(s) NVD
9.8
CVSS
48.7%
EPSS
⚡ 53.8
CVE-2014-7236 CRITICAL

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Feb 17, 2020 7 affected product(s) NVD
9.1
CVSS
55.6%
EPSS
⚡ 53.1
CVE-2020-9374 CRITICAL

On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

Feb 24, 2020 1 affected product(s) NVD
9.8
CVSS
42.7%
EPSS
⚡ 52
CVE-2020-4210 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.5%
EPSS
⚡ 43.8
CVE-2020-4213 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.5%
EPSS
⚡ 43.8
CVE-2020-4222 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.5%
EPSS
⚡ 43.8
CVE-2020-4212 CRITICAL

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.

Feb 24, 2020 2 affected product(s) NVD
9.8
CVSS
15.0%
EPSS
⚡ 43.7
CVE-2014-4170 CRITICAL

A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

Feb 13, 2020 1 affected product(s) NVD
9.8
CVSS
14.5%
EPSS
⚡ 43.5
CVE-2020-3760 CRITICAL

Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Feb 13, 2020 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2019-5138 CRITICAL

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020 1 affected product(s) NVD
9.9
CVSS
5.2%
EPSS
⚡ 41.1
CVE-2020-3765 CRITICAL

Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

Feb 20, 2020 1 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41
CVE-2020-3752 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2014-4678 CRITICAL

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

Feb 20, 2020 4 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2020-3749 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2020-3750 CRITICAL

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

Feb 13, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7