CSV
14,741 results for "vulnerability" Page 62
CVE-2018-0171 CRITICAL KEV Exploit

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.

Mar 28, 2018 1 affected product(s) NVD
9.8
CVSS
99.5%
EPSS
⚡ 99
CVE-2018-0151 CRITICAL KEV Exploit

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulnerability is due to incorrect bounds checking of certain values in packets that are destined for UDP port 18999 of an affected device. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the packets are processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code on the affected device with elevated privileges. The attacker could also leverage this vulnerability to cause the device to reload, causing a temporary DoS condition while the device is reloading. The malicious packets must be destined to and processed by an affected device. Traffic transiting a device will not trigger the vulnerability. Cisco Bug IDs: CSCvf73881.

Mar 28, 2018 2 affected product(s) NVD
9.8
CVSS
14.3%
EPSS
⚡ 73.5
CVE-2018-9032 CRITICAL

An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.

Mar 27, 2018 1 affected product(s) NVD
9.8
CVSS
27.8%
EPSS
⚡ 47.6
CVE-2018-9230 CRITICAL

In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty

Apr 2, 2018 1 affected product(s) NVD
9.8
CVSS
13.5%
EPSS
⚡ 43.2
CVE-2018-5474 CRITICAL

Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execute arbitrary code or cause the application to crash.

Mar 26, 2018 2 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2018-1295 CRITICAL

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.

Apr 2, 2018 1 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.1
CVE-2017-12815 CRITICAL

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

Mar 26, 2018 1 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2018-0150 CRITICAL

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software Release 16.x. This vulnerability does not affect Cisco IOS XE Software releases prior to Release 16.x. Cisco Bug IDs: CSCve89880.

Mar 28, 2018 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2018-4841 CRITICAL

A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow to cause a denial-of-service, or read and manipulate data as well as configuration settings of the affected device. At the stage of publishing this security advisory no public exploitation is known. Siemens provides mitigations to resolve it.

Mar 29, 2018 1 affected product(s) NVD
9.8
CVSS
4.8%
EPSS
⚡ 40.6
CVE-2018-9035 CRITICAL

CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.

Apr 4, 2018 1 affected product(s) NVD
9.6
CVSS
7.4%
EPSS
⚡ 40.6
CVE-2016-10230 CRITICAL

A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2016-8717 CRITICAL

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.

Apr 2, 2018 1 affected product(s) NVD
9.8
CVSS
2.1%
EPSS
⚡ 39.8
CVE-2018-1237 CRITICAL

Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central management of ScaleIO nodes. A remote malicious user, having network access to LIA, could potentially exploit this vulnerability to launch brute force guessing of user names and passwords of user accounts on the LIA.

Mar 27, 2018 1 affected product(s) NVD
9.8
CVSS
1.6%
EPSS
⚡ 39.7
CVE-2014-4959 CRITICAL

**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.

Mar 27, 2018 1 affected product(s) NVD
9.8
CVSS
1.5%
EPSS
⚡ 39.6
CVE-2015-9014 CRITICAL

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393750.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
1.4%
EPSS
⚡ 39.6
CVE-2014-9953 CRITICAL

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714770.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5
CVE-2014-9954 CRITICAL

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36388559.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5
CVE-2014-9955 CRITICAL

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384686.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5
CVE-2014-9956 CRITICAL

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36389611.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5
CVE-2014-9957 CRITICAL

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36387564.

Apr 4, 2018 1 affected product(s) NVD
9.8
CVSS
1.1%
EPSS
⚡ 39.5