CSV
14,784 results for "vulnerability" Page 145
CVE-2020-0796 CRITICAL KEV Exploit

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

Mar 12, 2020 8 affected product(s) NVD
10.0
CVSS
99.8%
EPSS
⚡ 99.9
CVE-2020-9054 CRITICAL KEV Exploit

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2

Mar 4, 2020 27 affected product(s) NVD
9.8
CVSS
100.0%
EPSS
⚡ 99.2
CVE-2020-8598 CRITICAL

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

Mar 18, 2020 7 affected product(s) NVD
9.8
CVSS
13.2%
EPSS
⚡ 43.2
CVE-2020-8540 CRITICAL

An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Mar 11, 2020 1 affected product(s) NVD
9.8
CVSS
12.8%
EPSS
⚡ 43
CVE-2020-9347 CRITICAL

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products

Mar 16, 2020 15 affected product(s) NVD
9.8
CVSS
7.8%
EPSS
⚡ 41.5
CVE-2020-0872 CRITICAL

A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.

Mar 12, 2020 1 affected product(s) NVD
9.6
CVSS
10.1%
EPSS
⚡ 41.4
CVE-2020-0690 CRITICAL

An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.

Mar 12, 2020 12 affected product(s) NVD
9.8
CVSS
7.0%
EPSS
⚡ 41.3
CVE-2020-10224 CRITICAL

An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

Mar 8, 2020 1 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2020-10225 CRITICAL

An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

Mar 8, 2020 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2020-10108 CRITICAL

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

Mar 12, 2020 11 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2019-13192 CRITICAL

Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.

Mar 13, 2020 305 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2020-10109 CRITICAL

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.

Mar 12, 2020 8 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2020-0902 CRITICAL

An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.

Mar 12, 2020 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2019-13172 CRITICAL

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2019-13165 CRITICAL

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40
CVE-2019-13168 CRITICAL

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40
CVE-2019-13169 CRITICAL

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-13197 CRITICAL

Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the URI paths of the web application that would allow an unauthenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-13201 CRITICAL

Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) in the LPD service and potentially execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2019-13202 CRITICAL

Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several functionalities of the web application that would allow an unauthenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40