CSV
14,738 results for "vulnerability" Page 32
CVE-2017-9828 CRITICAL Exploit

'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.

Jun 23, 2017 3 affected product(s) NVD
9.8
CVSS
82.5%
EPSS
⚡ 73.9
CVE-2017-3078 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
30.9%
EPSS
⚡ 48.5
CVE-2017-2805 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the device to trigger this vulnerability.

Jun 21, 2017 1 affected product(s) NVD
9.8
CVSS
26.2%
EPSS
⚡ 47.1
CVE-2017-8589 CRITICAL

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

Jul 11, 2017 12 affected product(s) NVD
9.8
CVSS
26.2%
EPSS
⚡ 47
CVE-2017-3076 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
24.7%
EPSS
⚡ 46.6
CVE-2017-3077 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
22.3%
EPSS
⚡ 45.9
CVE-2017-3081 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
14.4%
EPSS
⚡ 43.5
CVE-2017-3083 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
14.4%
EPSS
⚡ 43.5
CVE-2017-3082 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
11.7%
EPSS
⚡ 42.7
CVE-2017-9629 CRITICAL

A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow a remote attacker to execute arbitrary code in the context of a highly privileged account.

Jul 7, 2017 1 affected product(s) NVD
9.8
CVSS
9.8%
EPSS
⚡ 42.1
CVE-2017-3084 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2017-3088 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
10.0
CVSS
6.2%
EPSS
⚡ 41.8
CVE-2017-3090 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2017-3092 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2017-10682 CRITICAL

SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.

Jun 29, 2017 1 affected product(s) NVD
9.8
CVSS
8.2%
EPSS
⚡ 41.7
CVE-2017-3079 CRITICAL

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 4 affected product(s) NVD
9.8
CVSS
7.0%
EPSS
⚡ 41.3
CVE-2017-3086 CRITICAL

Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
6.9%
EPSS
⚡ 41.3
CVE-2017-3097 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2017-3098 CRITICAL

Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
6.9%
EPSS
⚡ 41.3
CVE-2017-3089 CRITICAL

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF imaging model. Successful exploitation could lead to arbitrary code execution.

Jun 20, 2017 1 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41