CSV
14,735 results for "vulnerability" Page 35
CVE-2017-11394 CRITICAL

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.

Aug 3, 2017 2 affected product(s) NVD
9.8
CVSS
66.8%
EPSS
⚡ 59.2
CVE-2017-8658 CRITICAL

A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".

Aug 11, 2017 1 affected product(s) NVD
9.8
CVSS
20.1%
EPSS
⚡ 45.2
CVE-2017-9800 CRITICAL

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

Aug 11, 2017 12 affected product(s) NVD
9.8
CVSS
18.9%
EPSS
⚡ 44.9
CVE-2017-11151 CRITICAL

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.

Aug 8, 2017 2 affected product(s) NVD
9.8
CVSS
16.3%
EPSS
⚡ 44.1
CVE-2017-11393 CRITICAL

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.

Aug 3, 2017 2 affected product(s) NVD
9.8
CVSS
15.9%
EPSS
⚡ 44
CVE-2017-11153 CRITICAL

Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.

Aug 8, 2017 2 affected product(s) NVD
9.8
CVSS
12.2%
EPSS
⚡ 42.9
CVE-2017-11274 CRITICAL

Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Aug 11, 2017 1 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2017-3108 CRITICAL

Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.

Aug 11, 2017 1 affected product(s) NVD
9.8
CVSS
8.6%
EPSS
⚡ 41.8
CVE-2015-0780 CRITICAL

SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Aug 9, 2017 1 affected product(s) NVD
9.8
CVSS
8.2%
EPSS
⚡ 41.7
CVE-2017-3124 CRITICAL

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the picture exchange (PCX) file format parsing module. Successful exploitation could lead to arbitrary code execution.

Aug 11, 2017 8 affected product(s) NVD
9.8
CVSS
8.3%
EPSS
⚡ 41.7
CVE-2015-0782 CRITICAL

SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Aug 9, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2017-10137 CRITICAL

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JNDI). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Aug 8, 2017 2 affected product(s) NVD
10.0
CVSS
3.8%
EPSS
⚡ 41.1
CVE-2017-6747 CRITICAL

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenticating with a valid external user account that matches an internal username and incorrectly receiving the authorization policy of the internal account. An exploit could allow the attacker to have Super Admin privileges for the ISE Admin portal. This vulnerability does not affect endpoints authenticating to the ISE. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance running Release 1.3, 1.4, 2.0.0, 2.0.1, or 2.1.0. Release 2.2.x is not affected. Cisco Bug IDs: CSCvb10995.

Aug 7, 2017 18 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2017-12939 CRITICAL

A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.

Aug 18, 2017 14 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2015-0781 CRITICAL

Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.

Aug 9, 2017 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2017-10202 CRITICAL

Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of OJVM. Note: This score is for Windows platforms. On non-Windows platforms Scope is Unchanged, giving a CVSS Base Score of 8.8. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Aug 8, 2017 3 affected product(s) NVD
9.9
CVSS
2.3%
EPSS
⚡ 40.3
CVE-2017-3632 CRITICAL

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: CDE Calendar). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. Note: CVE-2017-3632 is assigned to the "EASYSTREET" vulnerability. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Aug 8, 2017 2 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2017-6869 CRITICAL

A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.

Aug 8, 2017 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2017-10816 CRITICAL

SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.

Aug 4, 2017 2 affected product(s) NVD
9.8
CVSS
2.2%
EPSS
⚡ 39.9
CVE-2015-3616 CRITICAL

SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.

Aug 11, 2017 13 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9