CSV
14,737 results for "vulnerability" Page 31
CVE-2017-7494 CRITICAL KEV Exploit

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

May 30, 2017 5 affected product(s) NVD
9.8
CVSS
99.4%
EPSS
⚡ 99
CVE-2017-8543 CRITICAL KEV Exploit

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

Jun 15, 2017 17 affected product(s) NVD
9.8
CVSS
64.1%
EPSS
⚡ 88.4
CVE-2017-6639 CRITICAL

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The vulnerability is due to the lack of authentication and authorization mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could exploit this vulnerability by remotely connecting to the debugging tool via TCP. A successful exploit could allow the attacker to access sensitive information about the affected software or execute arbitrary code with root privileges on the affected system. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software Releases 10.1(1) and 10.1(2) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd09961.

Jun 8, 2017 3 affected product(s) NVD
9.8
CVSS
35.4%
EPSS
⚡ 49.8
CVE-2017-3078 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
30.9%
EPSS
⚡ 48.5
CVE-2017-2805 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the device to trigger this vulnerability.

Jun 21, 2017 1 affected product(s) NVD
9.8
CVSS
26.2%
EPSS
⚡ 47.1
CVE-2017-3076 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
24.7%
EPSS
⚡ 46.6
CVE-2017-3077 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
22.3%
EPSS
⚡ 45.9
CVE-2017-4901 CRITICAL

The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.

Jun 8, 2017 18 affected product(s) NVD
9.9
CVSS
19.9%
EPSS
⚡ 45.6
CVE-2017-3081 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
14.4%
EPSS
⚡ 43.5
CVE-2017-3083 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
14.4%
EPSS
⚡ 43.5
CVE-2017-3082 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
11.7%
EPSS
⚡ 42.7
CVE-2017-6640 CRITICAL

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to the affected software by using the credentials for this default user account. A successful exploit could allow the attacker to use this default user account to log in to the affected software and gain access to the administrative console of a DCNM server. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software releases prior to Release 10.2(1) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd95346.

Jun 8, 2017 3 affected product(s) NVD
9.8
CVSS
10.7%
EPSS
⚡ 42.4
CVE-2017-3075 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2017-3084 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2017-3088 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
10.0
CVSS
6.2%
EPSS
⚡ 41.8
CVE-2017-3090 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2017-3092 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2017-3079 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
7.0%
EPSS
⚡ 41.3
CVE-2017-3086 CRITICAL

Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
6.9%
EPSS
⚡ 41.3
CVE-2017-3097 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3