CSV
14,741 results for "vulnerability" Page 58
CVE-2018-6530 CRITICAL KEV Exploit

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

Mar 6, 2018 4 affected product(s) NVD
9.8
CVSS
96.7%
EPSS
⚡ 98.2
CVE-2018-0147 CRITICAL KEV Exploit

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988.

Mar 8, 2018 1 affected product(s) NVD
9.8
CVSS
18.3%
EPSS
⚡ 74.7
CVE-2018-7297 CRITICAL

Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

Feb 22, 2018 1 affected product(s) NVD
9.8
CVSS
64.3%
EPSS
⚡ 58.5
CVE-2018-7314 CRITICAL

SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

Feb 22, 2018 1 affected product(s) NVD
9.8
CVSS
57.8%
EPSS
⚡ 56.5
CVE-2018-7300 CRITICAL

Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

Feb 22, 2018 1 affected product(s) NVD
9.8
CVSS
30.6%
EPSS
⚡ 48.4
CVE-2018-4879 CRITICAL

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that processes Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

Feb 27, 2018 6 affected product(s) NVD
9.8
CVSS
28.6%
EPSS
⚡ 47.8
CVE-2018-1216 CRITICAL

A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.

Mar 8, 2018 4 affected product(s) NVD
9.8
CVSS
21.7%
EPSS
⚡ 45.7
CVE-2018-6481 CRITICAL

A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

Feb 27, 2018 1 affected product(s) NVD
9.8
CVSS
20.7%
EPSS
⚡ 45.4
CVE-2017-8975 CRITICAL

A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

Feb 15, 2018 1 affected product(s) NVD
9.8
CVSS
18.2%
EPSS
⚡ 44.7
CVE-2017-8976 CRITICAL

A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

Feb 15, 2018 1 affected product(s) NVD
9.8
CVSS
18.2%
EPSS
⚡ 44.7
CVE-2018-4872 CRITICAL

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is a security bypass vulnerability that leads to a sandbox escape. Specifically, the vulnerability exists in the way a cross call is handled.

Feb 27, 2018 6 affected product(s) NVD
10.0
CVSS
11.5%
EPSS
⚡ 43.5
CVE-2015-5377 CRITICAL

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

Mar 6, 2018 1 affected product(s) NVD
9.8
CVSS
14.3%
EPSS
⚡ 43.5
CVE-2018-4895 CRITICAL

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

Feb 27, 2018 6 affected product(s) NVD
9.8
CVSS
13.7%
EPSS
⚡ 43.3
CVE-2017-8981 CRITICAL

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.

Feb 15, 2018 1 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2018-1000116 CRITICAL

NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.

Mar 7, 2018 2 affected product(s) NVD
9.8
CVSS
6.3%
EPSS
⚡ 41.1
CVE-2018-0124 CRITICAL

A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key generation during application configuration. An attacker could exploit this vulnerability by using a known insecure key value to bypass security protections by sending arbitrary requests using the insecure key to a targeted application. An exploit could allow the attacker to execute arbitrary code. This vulnerability affects Cisco Unified Communications Domain Manager releases prior to 11.5(2). Cisco Bug IDs: CSCuv67964.

Feb 22, 2018 1 affected product(s) NVD
9.8
CVSS
5.1%
EPSS
⚡ 40.7
CVE-2018-1164 CRITICAL

This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numerous exposed CGI endpoints. The vulnerability is caused by improper access controls that allow access to critical functions without authentication. An attacker can use this vulnerability to reboot affected devices, along with other actions. Was ZDI-CAN-4540.

Feb 21, 2018 1 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2017-18211 CRITICAL

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.

Mar 1, 2018 30 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2018-5469 CRITICAL

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.

Mar 6, 2018 134 affected product(s) NVD
9.8
CVSS
2.8%
EPSS
⚡ 40.1
CVE-2018-5991 CRITICAL

SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.

Feb 17, 2018 1 affected product(s) NVD
9.8
CVSS
2.7%
EPSS
⚡ 40