CSV
14,737 results for "vulnerability" Page 27
CVE-2017-3881 CRITICAL KEV Exploit

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.

Mar 17, 2017 2 affected product(s) NVD
9.8
CVSS
99.0%
EPSS
⚡ 98.9
CVE-2016-2555 CRITICAL Exploit

SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.

Apr 13, 2017 1 affected product(s) NVD
9.8
CVSS
79.6%
EPSS
⚡ 73.1
CVE-2017-7581 CRITICAL

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.

Apr 7, 2017 1 affected product(s) NVD
9.8
CVSS
48.4%
EPSS
⚡ 53.7
CVE-2017-6517 CRITICAL

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

Mar 23, 2017 1 affected product(s) NVD
9.8
CVSS
46.3%
EPSS
⚡ 53.1
CVE-2017-5334 CRITICAL

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.

Mar 24, 2017 11 affected product(s) NVD
9.8
CVSS
32.8%
EPSS
⚡ 49
CVE-2017-0561 CRITICAL

A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199105. References: B-RB#110814.

Apr 7, 2017 2 affected product(s) NVD
9.8
CVSS
29.8%
EPSS
⚡ 48.1
CVE-2017-3061 CRITICAL

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.

Apr 12, 2017 4 affected product(s) NVD
9.8
CVSS
24.7%
EPSS
⚡ 46.6
CVE-2015-8556 CRITICAL

Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.

Mar 24, 2017 1 affected product(s) NVD
10.0
CVSS
13.4%
EPSS
⚡ 44
CVE-2017-7722 CRITICAL

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.

Apr 12, 2017 1 affected product(s) NVD
10.0
CVSS
12.7%
EPSS
⚡ 43.8
CVE-2017-6972 CRITICAL

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.

Mar 22, 2017 3 affected product(s) NVD
9.8
CVSS
14.6%
EPSS
⚡ 43.6
CVE-2017-7230 CRITICAL

A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.

Mar 22, 2017 1 affected product(s) NVD
9.8
CVSS
13.8%
EPSS
⚡ 43.3
CVE-2017-3059 CRITICAL

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object. Successful exploitation could lead to arbitrary code execution.

Apr 12, 2017 4 affected product(s) NVD
9.8
CVSS
9.5%
EPSS
⚡ 42.1
CVE-2017-3062 CRITICAL

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

Apr 12, 2017 4 affected product(s) NVD
9.8
CVSS
9.5%
EPSS
⚡ 42.1
CVE-2017-3063 CRITICAL

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class. Successful exploitation could lead to arbitrary code execution.

Apr 12, 2017 4 affected product(s) NVD
9.8
CVSS
8.9%
EPSS
⚡ 41.9
CVE-2017-3853 CRITICAL

A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remote code execution with root privileges in the virtual instance running on an affected device. The vulnerability is due to insufficient bounds checking in the DMo process. An attacker could exploit this vulnerability by sending crafted packets that are forwarded to the DMo process for evaluation. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. This vulnerability affects the following Cisco 800 Series Industrial Integrated Services Routers: Cisco IR809 and Cisco IR829. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52330.

Mar 22, 2017 2 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2017-3060 CRITICAL

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.

Apr 12, 2017 4 affected product(s) NVD
9.8
CVSS
7.6%
EPSS
⚡ 41.5
CVE-2017-3037 CRITICAL

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution.

Apr 12, 2017 6 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2017-7689 CRITICAL

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

Apr 11, 2017 1 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.9
CVE-2014-5009 CRITICAL

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

Mar 31, 2017 4 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2017-3010 CRITICAL

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine. Successful exploitation could lead to arbitrary code execution.

Mar 31, 2017 6 affected product(s) NVD
9.8
CVSS
4.6%
EPSS
⚡ 40.6