CSV
14,733 results for "vulnerability" Page 47
CVE-2017-11283 CRITICAL

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

Dec 1, 2017 18 affected product(s) NVD
9.8
CVSS
42.7%
EPSS
⚡ 52
CVE-2017-11284 CRITICAL

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

Dec 1, 2017 18 affected product(s) NVD
9.8
CVSS
42.7%
EPSS
⚡ 52
CVE-2017-11282 CRITICAL

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

Dec 1, 2017 7 affected product(s) NVD
9.8
CVSS
34.8%
EPSS
⚡ 49.7
CVE-2017-11281 CRITICAL

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

Dec 1, 2017 7 affected product(s) NVD
9.8
CVSS
33.9%
EPSS
⚡ 49.4
CVE-2017-16844 CRITICAL

Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.

Nov 16, 2017 1 affected product(s) NVD
9.8
CVSS
12.5%
EPSS
⚡ 43
CVE-2017-14746 CRITICAL

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

Nov 27, 2017 16 affected product(s) NVD
9.8
CVSS
9.9%
EPSS
⚡ 42.2
CVE-2017-15702 CRITICAL

In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port. The attacker still needs valid credentials with the authentication provider on the spoofed port. This becomes an issue when the spoofed port has weaker authentication protection (e.g., anonymous access, default accounts) and is normally protected by firewall rules or similar which can be circumvented by this vulnerability. AMQP ports are not affected. Versions 6.0.0 and newer are not affected.

Dec 1, 2017 1 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2017-14378 CRITICAL

EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability."

Nov 29, 2017 2 affected product(s) NVD
10.0
CVSS
3.0%
EPSS
⚡ 40.9
CVE-2017-8020 CRITICAL

An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allow a remote unauthenticated attacker to execute arbitrary commands with root privileges on an affected server.

Nov 28, 2017 4 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2017-14586 CRITICAL

The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.

Nov 27, 2017 1 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.3
CVE-2017-14377 CRITICAL

EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnerability that could potentially lead to authentication bypass.

Nov 29, 2017 2 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2017-1000231 CRITICAL

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

Nov 17, 2017 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2017-2738 CRITICAL

VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of authentication for accessing web pages. An unauthenticated attacker could bypass the authentication by sending a crafted HTTP request. 5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.

Nov 22, 2017 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40
CVE-2017-14189 CRITICAL

An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.

Nov 29, 2017 1 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40
CVE-2017-1000232 CRITICAL

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

Nov 17, 2017 1 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9
CVE-2017-5719 CRITICAL

A vulnerability in the Intel Deep Learning Training Tool Beta 1 allows a network attacker to remotely execute code as a local user.

Nov 21, 2017 1 affected product(s) NVD
9.8
CVSS
1.7%
EPSS
⚡ 39.7
CVE-2017-13071 CRITICAL

QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.

Nov 22, 2017 2 affected product(s) NVD
9.8
CVSS
1.4%
EPSS
⚡ 39.6
CVE-2017-8122 CRITICAL

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

Nov 22, 2017 1 affected product(s) NVD
9.8
CVSS
1.3%
EPSS
⚡ 39.6
CVE-2017-10898 CRITICAL

SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.

Dec 1, 2017 2 affected product(s) NVD
9.8
CVSS
1.3%
EPSS
⚡ 39.6
CVE-2017-10899 CRITICAL

SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.

Dec 1, 2017 2 affected product(s) NVD
9.8
CVSS
1.3%
EPSS
⚡ 39.6