CSV
14,737 results for "vulnerability" Page 26
CVE-2017-3881 CRITICAL KEV Exploit

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.

Mar 17, 2017 2 affected product(s) NVD
9.8
CVSS
99.0%
EPSS
⚡ 98.9
CVE-2017-7581 CRITICAL

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.

Apr 7, 2017 1 affected product(s) NVD
9.8
CVSS
48.4%
EPSS
⚡ 53.7
CVE-2017-6517 CRITICAL

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

Mar 23, 2017 1 affected product(s) NVD
9.8
CVSS
46.3%
EPSS
⚡ 53.1
CVE-2017-5334 CRITICAL

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.

Mar 24, 2017 11 affected product(s) NVD
9.8
CVSS
32.8%
EPSS
⚡ 49
CVE-2017-5674 CRITICAL

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password.

Mar 13, 2017 1 affected product(s) NVD
9.8
CVSS
21.6%
EPSS
⚡ 45.7
CVE-2015-8556 CRITICAL

Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.

Mar 24, 2017 1 affected product(s) NVD
10.0
CVSS
13.4%
EPSS
⚡ 44
CVE-2017-6558 CRITICAL

iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.

Mar 9, 2017 1 affected product(s) NVD
9.8
CVSS
15.3%
EPSS
⚡ 43.8
CVE-2017-6972 CRITICAL

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.

Mar 22, 2017 3 affected product(s) NVD
9.8
CVSS
14.6%
EPSS
⚡ 43.6
CVE-2017-7230 CRITICAL

A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.

Mar 22, 2017 1 affected product(s) NVD
9.8
CVSS
13.8%
EPSS
⚡ 43.3
CVE-2017-6506 CRITICAL

In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

Mar 10, 2017 1 affected product(s) NVD
9.8
CVSS
11.7%
EPSS
⚡ 42.7
CVE-2017-3853 CRITICAL

A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remote code execution with root privileges in the virtual instance running on an affected device. The vulnerability is due to insufficient bounds checking in the DMo process. An attacker could exploit this vulnerability by sending crafted packets that are forwarded to the DMo process for evaluation. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. This vulnerability affects the following Cisco 800 Series Industrial Integrated Services Routers: Cisco IR809 and Cisco IR829. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52330.

Mar 22, 2017 2 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2016-8027 CRITICAL

SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.

Mar 14, 2017 2 affected product(s) NVD
10.0
CVSS
5.7%
EPSS
⚡ 41.7
CVE-2017-5929 CRITICAL

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Mar 13, 2017 3 affected product(s) NVD
9.8
CVSS
7.5%
EPSS
⚡ 41.5
CVE-2017-3831 CRITICAL

A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device. This vulnerability affects Cisco Mobility Express 1800 Series Access Points running a software version prior to 8.2.110.0. Cisco Bug IDs: CSCuy68219.

Mar 15, 2017 4 affected product(s) NVD
9.8
CVSS
5.3%
EPSS
⚡ 40.8
CVE-2014-5009 CRITICAL

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

Mar 31, 2017 4 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2017-3010 CRITICAL

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine. Successful exploitation could lead to arbitrary code execution.

Mar 31, 2017 6 affected product(s) NVD
9.8
CVSS
4.6%
EPSS
⚡ 40.6
CVE-2017-6023 CRITICAL

An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior to V3.6 Build 170215, and CM25E versions prior to V3.6 Build 170215. A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution or crash the affected device.

Mar 16, 2017 4 affected product(s) NVD
9.8
CVSS
4.4%
EPSS
⚡ 40.5
CVE-2017-3834 CRITICAL

A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerability is due to the existence of default credentials for an affected device that is running Cisco Mobility Express Software, regardless of whether the device is configured as a master, subordinate, or standalone access point. An attacker who has layer 3 connectivity to an affected device could use Secure Shell (SSH) to log in to the device with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points that are running an 8.2.x release of Cisco Mobility Express Software prior to Release 8.2.111.0, regardless of whether the device is configured as a master, subordinate, or standalone access point. Release 8.2 was the first release of Cisco Mobility Express Software for next generation Cisco Aironet Access Points. Cisco Bug IDs: CSCva50691.

Apr 6, 2017 8 affected product(s) NVD
9.8
CVSS
4.5%
EPSS
⚡ 40.5
CVE-2017-7318 CRITICAL

Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.

Mar 30, 2017 1 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2016-9019 CRITICAL

SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.

Mar 7, 2017 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2