CSV
14,737 results for "vulnerability" Page 21
CVE-2016-10045 CRITICAL Exploit

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

Dec 30, 2016 3 affected product(s) NVD
9.8
CVSS
98.0%
EPSS
⚡ 78.6
CVE-2016-8582 CRITICAL

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

Oct 28, 2016 2 affected product(s) NVD
9.8
CVSS
57.4%
EPSS
⚡ 56.4
CVE-2016-9565 CRITICAL

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

Dec 15, 2016 1 affected product(s) NVD
9.8
CVSS
22.7%
EPSS
⚡ 46
CVE-2016-7866 CRITICAL

Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 15, 2016 1 affected product(s) NVD
9.8
CVSS
15.8%
EPSS
⚡ 43.9
CVE-2016-7277 CRITICAL

Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Dec 20, 2016 1 affected product(s) NVD
9.6
CVSS
18.0%
EPSS
⚡ 43.8
CVE-2016-8339 CRITICAL

A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.

Oct 28, 2016 4 affected product(s) NVD
9.8
CVSS
14.8%
EPSS
⚡ 43.7
CVE-2016-8205 CRITICAL

A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.

Jan 14, 2017 1 affected product(s) NVD
9.8
CVSS
13.0%
EPSS
⚡ 43.1
CVE-2015-3210 CRITICAL

Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability than CVE-2015-8384.

Dec 13, 2016 5 affected product(s) NVD
9.8
CVSS
9.2%
EPSS
⚡ 41.9
CVE-2015-2868 CRITICAL

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

Jan 6, 2017 1 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.3
CVE-2016-8204 CRITICAL

A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.

Jan 14, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2016-7886 CRITICAL

Adobe InDesign version 11.4.1 and earlier, Adobe InDesign Server 11.0.0 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 15, 2016 2 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2015-4594 CRITICAL

eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

Jan 10, 2017 1 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2016-9137 CRITICAL

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.

Jan 4, 2017 13 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2016-2339 CRITICAL

An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.

Jan 6, 2017 2 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2016-6441 CRITICAL

A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated, remote attacker to cause a reload of, or remotely execute code on, the affected system. This vulnerability affects Cisco ASR 900 Series Aggregation Services Routers (ASR902, ASR903, and ASR907) that are running the following releases of Cisco IOS XE Software: 3.17.0S 3.17.1S 3.17.2S 3.18.0S 3.18.1S. More Information: CSCuy15175. Known Affected Releases: 15.6(1)S 15.6(2)S. Known Fixed Releases: 15.6(1)S2.12 15.6(1.17)S0.41 15.6(1.17)SP 15.6(2)SP 16.4(0.183) 16.5(0.10).

Nov 3, 2016 7 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2016-7856 CRITICAL

Adobe DNG Converter versions 9.7 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 15, 2016 1 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2016-6448 CRITICAL

A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.

Nov 3, 2016 9 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2016-9835 CRITICAL

Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.

Dec 5, 2016 24 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2016-9427 CRITICAL

Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.

Dec 12, 2016 5 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2016-9936 CRITICAL

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.

Jan 4, 2017 14 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.4