CSV
14,733 results for "vulnerability" Page 49
CVE-2017-17411 CRITICAL Exploit

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

Dec 21, 2017 1 affected product(s) NVD
9.8
CVSS
87.9%
EPSS
⚡ 75.6
CVE-2012-2576 CRITICAL

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

Dec 20, 2017 3 affected product(s) NVD
9.8
CVSS
59.4%
EPSS
⚡ 57
CVE-2017-3195 CRITICAL

Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.

Dec 16, 2017 7 affected product(s) NVD
9.8
CVSS
21.4%
EPSS
⚡ 45.6
CVE-2017-17672 CRITICAL

In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which is a publicly exposed API. This is exploited with the templateidlist parameter to ajax/api/template/cacheTemplates.

Dec 14, 2017 3 affected product(s) NVD
9.8
CVSS
15.2%
EPSS
⚡ 43.8
CVE-2017-17106 CRITICAL

Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages.

Dec 19, 2017 1 affected product(s) NVD
9.8
CVSS
15.3%
EPSS
⚡ 43.8
CVE-2017-16398 CRITICAL

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 8 affected product(s) NVD
9.8
CVSS
9.2%
EPSS
⚡ 42
CVE-2017-16725 CRITICAL

A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible.

Dec 20, 2017 139 affected product(s) NVD
9.8
CVSS
9.2%
EPSS
⚡ 42
CVE-2017-11293 CRITICAL

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 8 affected product(s) NVD
9.8
CVSS
9.1%
EPSS
⚡ 41.9
CVE-2017-11294 CRITICAL

An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
8.8%
EPSS
⚡ 41.9
CVE-2017-11291 CRITICAL

An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.

Dec 9, 2017 1 affected product(s) NVD
10.0
CVSS
5.5%
EPSS
⚡ 41.7
CVE-2017-11303 CRITICAL

An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
8.1%
EPSS
⚡ 41.6
CVE-2017-11304 CRITICAL

An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
7.1%
EPSS
⚡ 41.3
CVE-2017-11213 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.2
CVE-2017-11302 CRITICAL

An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.1
CVE-2017-3112 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2017-3114 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2017-11215 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2017-11225 CRITICAL

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 7 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2017-11295 CRITICAL

An issue was discovered in Adobe DNG Converter 9.12.1 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

Dec 9, 2017 1 affected product(s) NVD
9.8
CVSS
5.9%
EPSS
⚡ 41
CVE-2017-11899 CRITICAL

Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability".

Dec 12, 2017 7 affected product(s) NVD
9.8
CVSS
5.8%
EPSS
⚡ 41