CSV
14,737 results for "vulnerability" Page 22
CVE-2016-10045 CRITICAL Exploit

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

Dec 30, 2016 3 affected product(s) NVD
9.8
CVSS
98.0%
EPSS
⚡ 78.6
CVE-2017-3248 CRITICAL Exploit

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS v3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).

Jan 27, 2017 4 affected product(s) NVD
9.8
CVSS
97.3%
EPSS
⚡ 78.4
CVE-2016-6600 CRITICAL Exploit

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

Jan 23, 2017 2 affected product(s) NVD
9.8
CVSS
90.6%
EPSS
⚡ 76.4
CVE-2016-9565 CRITICAL

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

Dec 15, 2016 1 affected product(s) NVD
9.8
CVSS
22.7%
EPSS
⚡ 46
CVE-2017-3241 CRITICAL

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS v3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).

Jan 27, 2017 9 affected product(s) NVD
9.0
CVSS
32.8%
EPSS
⚡ 45.9
CVE-2016-7277 CRITICAL

Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Dec 20, 2016 1 affected product(s) NVD
9.6
CVSS
18.0%
EPSS
⚡ 43.8
CVE-2016-8205 CRITICAL

A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.

Jan 14, 2017 1 affected product(s) NVD
9.8
CVSS
13.0%
EPSS
⚡ 43.1
CVE-2016-9052 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_by_iname resulting in remote code execution. An attacker can simply connect to the port to trigger this vulnerability.

Jan 26, 2017 1 affected product(s) NVD
9.8
CVSS
7.7%
EPSS
⚡ 41.5
CVE-2016-9054 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_list_by_set_binid resulting in remote code execution. An attacker can simply connect to the port to trigger this vulnerability.

Jan 26, 2017 1 affected product(s) NVD
9.8
CVSS
7.7%
EPSS
⚡ 41.5
CVE-2015-2868 CRITICAL

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

Jan 6, 2017 1 affected product(s) NVD
9.8
CVSS
6.8%
EPSS
⚡ 41.3
CVE-2016-8204 CRITICAL

A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.

Jan 14, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2016-7886 CRITICAL

Adobe InDesign version 11.4.1 and earlier, Adobe InDesign Server 11.0.0 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Dec 15, 2016 2 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2015-4594 CRITICAL

eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

Jan 10, 2017 1 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2016-9137 CRITICAL

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.

Jan 4, 2017 13 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2016-2339 CRITICAL

An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.

Jan 6, 2017 2 affected product(s) NVD
9.8
CVSS
5.2%
EPSS
⚡ 40.8
CVE-2017-3324 CRITICAL

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera P6 Enterprise Project Portfolio Management. CVSS v3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).

Jan 27, 2017 7 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2016-6912 CRITICAL

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

Jan 26, 2017 1 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2016-9936 CRITICAL

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.

Jan 4, 2017 14 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.4
CVE-2016-7790 CRITICAL

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.

Jan 12, 2017 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2016-7791 CRITICAL

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which leads to arbitrary code execution.

Jan 12, 2017 1 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4