CSV
14,736 results for "vulnerability" Page 30
CVE-2017-7494 CRITICAL KEV Exploit

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

May 30, 2017 5 affected product(s) NVD
9.8
CVSS
99.4%
EPSS
⚡ 99
CVE-2017-8543 CRITICAL KEV Exploit

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

Jun 15, 2017 17 affected product(s) NVD
9.8
CVSS
64.1%
EPSS
⚡ 88.4
CVE-2017-8917 CRITICAL Exploit

SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

May 17, 2017 1 affected product(s) NVD
9.8
CVSS
99.8%
EPSS
⚡ 79.1
CVE-2017-8895 CRITICAL Exploit

In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.

May 10, 2017 3 affected product(s) NVD
9.8
CVSS
71.0%
EPSS
⚡ 70.5
CVE-2017-6622 CRITICAL

A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.

May 18, 2017 10 affected product(s) NVD
9.8
CVSS
62.2%
EPSS
⚡ 57.9
CVE-2017-5174 CRITICAL

An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.

May 19, 2017 1 affected product(s) NVD
9.8
CVSS
52.3%
EPSS
⚡ 54.9
CVE-2016-10329 CRITICAL

Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.

May 12, 2017 1 affected product(s) NVD
9.8
CVSS
40.8%
EPSS
⚡ 51.4
CVE-2015-4455 CRITICAL

Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.

May 23, 2017 1 affected product(s) NVD
9.8
CVSS
40.6%
EPSS
⚡ 51.4
CVE-2017-6639 CRITICAL

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The vulnerability is due to the lack of authentication and authorization mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could exploit this vulnerability by remotely connecting to the debugging tool via TCP. A successful exploit could allow the attacker to access sensitive information about the affected software or execute arbitrary code with root privileges on the affected system. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software Releases 10.1(1) and 10.1(2) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd09961.

Jun 8, 2017 3 affected product(s) NVD
9.8
CVSS
35.4%
EPSS
⚡ 49.8
CVE-2017-5173 CRITICAL

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

May 19, 2017 1 affected product(s) NVD
9.8
CVSS
29.6%
EPSS
⚡ 48.1
CVE-2017-4901 CRITICAL

The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.

Jun 8, 2017 18 affected product(s) NVD
9.9
CVSS
19.9%
EPSS
⚡ 45.6
CVE-2017-0223 CRITICAL

A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0252.

May 15, 2017 1 affected product(s) NVD
9.8
CVSS
14.7%
EPSS
⚡ 43.6
CVE-2017-0252 CRITICAL

A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0223.

May 15, 2017 1 affected product(s) NVD
9.8
CVSS
13.4%
EPSS
⚡ 43.2
CVE-2017-6640 CRITICAL

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to the affected software by using the credentials for this default user account. A successful exploit could allow the attacker to use this default user account to log in to the affected software and gain access to the administrative console of a DCNM server. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software releases prior to Release 10.2(1) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd95346.

Jun 8, 2017 3 affected product(s) NVD
9.8
CVSS
10.7%
EPSS
⚡ 42.4
CVE-2017-2800 CRITICAL

A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the attacker needs to supply a malicious x509 certificate to either a server or a client application using this library.

May 24, 2017 1 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.8
CVE-2017-3075 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2016-7978 CRITICAL

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

May 23, 2017 1 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.9
CVE-2017-4918 CRITICAL

VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed.

Jun 8, 2017 14 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2017-6667 CRITICAL

A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server. More Information: CSCvb66730. Known Affected Releases: 2.0.

Jun 13, 2017 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.7
CVE-2017-6821 CRITICAL

Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.

May 23, 2017 1 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3