CSV
14,733 results for "vulnerability" Page 48
CVE-2017-11283 CRITICAL

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

Dec 1, 2017 18 affected product(s) NVD
9.8
CVSS
42.7%
EPSS
⚡ 52
CVE-2017-11284 CRITICAL

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

Dec 1, 2017 18 affected product(s) NVD
9.8
CVSS
42.7%
EPSS
⚡ 52
CVE-2017-11282 CRITICAL

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

Dec 1, 2017 7 affected product(s) NVD
9.8
CVSS
34.8%
EPSS
⚡ 49.7
CVE-2017-11281 CRITICAL

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

Dec 1, 2017 7 affected product(s) NVD
9.8
CVSS
33.9%
EPSS
⚡ 49.4
CVE-2017-14746 CRITICAL

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

Nov 27, 2017 16 affected product(s) NVD
9.8
CVSS
9.9%
EPSS
⚡ 42.2
CVE-2017-16398 CRITICAL

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 8 affected product(s) NVD
9.8
CVSS
9.2%
EPSS
⚡ 42
CVE-2017-11293 CRITICAL

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 8 affected product(s) NVD
9.8
CVSS
9.1%
EPSS
⚡ 41.9
CVE-2017-11294 CRITICAL

An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
8.8%
EPSS
⚡ 41.9
CVE-2017-11291 CRITICAL

An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.

Dec 9, 2017 1 affected product(s) NVD
10.0
CVSS
5.5%
EPSS
⚡ 41.7
CVE-2017-11303 CRITICAL

An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2017-11304 CRITICAL

An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2017-11213 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2017-15702 CRITICAL

In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port. The attacker still needs valid credentials with the authentication provider on the spoofed port. This becomes an issue when the spoofed port has weaker authentication protection (e.g., anonymous access, default accounts) and is normally protected by firewall rules or similar which can be circumvented by this vulnerability. AMQP ports are not affected. Versions 6.0.0 and newer are not affected.

Dec 1, 2017 1 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2017-11302 CRITICAL

An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.1
CVE-2017-3112 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2017-11215 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2017-11225 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2017-11295 CRITICAL

An issue was discovered in Adobe DNG Converter 9.12.1 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41
CVE-2017-14378 CRITICAL

EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability."

Nov 29, 2017 2 affected product(s) NVD
10.0
CVSS
3.0%
EPSS
⚡ 40.9
CVE-2017-17480 CRITICAL

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

Dec 8, 2017 4 affected product(s) NVD
9.8
CVSS
5.1%
EPSS
⚡ 40.7