CSV
14,738 results for "vulnerability" Page 37
CVE-2017-12965 CRITICAL

Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

Aug 23, 2017 1 affected product(s) NVD
9.8
CVSS
15.7%
EPSS
⚡ 43.9
CVE-2015-8352 CRITICAL

Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.

Aug 24, 2017 1 affected product(s) NVD
9.8
CVSS
15.6%
EPSS
⚡ 43.9
CVE-2017-12791 CRITICAL

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

Aug 23, 2017 2 affected product(s) NVD
9.8
CVSS
4.7%
EPSS
⚡ 40.6
CVE-2017-12858 CRITICAL

Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.

Aug 23, 2017 1 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2017-7420 CRITICAL

An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275).

Aug 21, 2017 7 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9
CVE-2014-8428 CRITICAL

Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

Aug 28, 2017 1 affected product(s) NVD
9.8
CVSS
2.4%
EPSS
⚡ 39.9
CVE-2017-7278 CRITICAL

Unspecified vulnerability in ASSA ABLOY APTUS Styra Porttelefonkort 4400 before A2 has unknown impact and attack vectors.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
1.8%
EPSS
⚡ 39.7
CVE-2017-12776 CRITICAL

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
1.4%
EPSS
⚡ 39.6
CVE-2015-8593 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
1.2%
EPSS
⚡ 39.6
CVE-2014-9968 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.9%
EPSS
⚡ 39.5
CVE-2014-9976 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5
CVE-2014-9977 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in PlayReady DRM.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.9%
EPSS
⚡ 39.5
CVE-2014-9978 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE service.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.9%
EPSS
⚡ 39.5
CVE-2015-8594 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in RFA-1x.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5
CVE-2015-8595 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in digital television/digital radio DRM.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.8%
EPSS
⚡ 39.5
CVE-2015-9039 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reached by a sequence of downlink messages.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.8%
EPSS
⚡ 39.5
CVE-2015-9041 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when performing WCDMA radio tuning.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.9%
EPSS
⚡ 39.5
CVE-2015-9042 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when processing a QMI message.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.9%
EPSS
⚡ 39.5
CVE-2015-9044 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.8%
EPSS
⚡ 39.5
CVE-2015-9045 CRITICAL

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GERAN where a buffer can be overflown while taking power measurements.

Aug 18, 2017 1 affected product(s) NVD
9.8
CVSS
0.8%
EPSS
⚡ 39.5