CSV
14,739 results for "vulnerability" Page 70
CVE-2018-10088 CRITICAL

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

Jun 8, 2018 1 affected product(s) NVD
9.8
CVSS
39.7%
EPSS
⚡ 51.1
CVE-2017-5375 CRITICAL

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 13 affected product(s) NVD
9.8
CVSS
33.5%
EPSS
⚡ 49.3
CVE-2016-9899 CRITICAL

Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Jun 11, 2018 22 affected product(s) NVD
9.8
CVSS
21.1%
EPSS
⚡ 45.5
CVE-2018-11586 CRITICAL

XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Jun 5, 2018 1 affected product(s) NVD
9.8
CVSS
15.0%
EPSS
⚡ 43.7
CVE-2017-16082 CRITICAL

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

Jun 7, 2018 6 affected product(s) NVD
9.8
CVSS
10.5%
EPSS
⚡ 42.4
CVE-2017-3202 CRITICAL

The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The ability to exploit this vulnerability depends on the availability of classes in the class path that make use of deserialization. A remote attacker with the ability to spoof or control information may be able to send serialized Java objects with pre-set properties that result in arbitrary code execution when deserialized.

Jun 11, 2018 1 affected product(s) NVD
9.8
CVSS
8.2%
EPSS
⚡ 41.7
CVE-2018-0315 CRITICAL

A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect memory operations that the affected software performs when the software parses a username during login authentication. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device or cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are running Cisco IOS XE Software Release Fuji 16.7.1 or Fuji 16.8.1 and are configured to use AAA for login authentication. Cisco Bug IDs: CSCvi25380.

Jun 7, 2018 2 affected product(s) NVD
9.8
CVSS
7.8%
EPSS
⚡ 41.5
CVE-2016-9063 CRITICAL

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Jun 11, 2018 9 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2018-11629 CRITICAL

Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

Jun 2, 2018 3 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-11681 CRITICAL

Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

Jun 2, 2018 3 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-11682 CRITICAL

Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

Jun 2, 2018 3 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2018-0320 CRITICAL

A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 12.1 and prior. Cisco Bug IDs: CSCvd61754.

Jun 7, 2018 2 affected product(s) NVD
9.8
CVSS
4.0%
EPSS
⚡ 40.4
CVE-2017-5390 CRITICAL

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2017-5396 CRITICAL

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2018-0321 CRITICAL

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this vulnerability by accessing the open RMI system on an affected PCP instance. An exploit could allow the attacker to perform malicious actions that affect PCP and the devices that are connected to it. This vulnerability affects Cisco Prime Collaboration Provisioning (PCP) Releases 11.6 and prior. Cisco Bug IDs: CSCvd61746.

Jun 7, 2018 3 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2016-5297 CRITICAL

An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

Jun 11, 2018 4 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2016-9898 CRITICAL

Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.3
CVE-2017-5398 CRITICAL

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Jun 11, 2018 20 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2016-5290 CRITICAL

Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

Jun 11, 2018 4 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-5373 CRITICAL

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 13 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2