CSV
14,737 results for "vulnerability" Page 82
CVE-2018-14847 CRITICAL KEV Exploit

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Aug 2, 2018 1 affected product(s) NVD
9.1
CVSS
96.1%
EPSS
⚡ 95.2
CVE-2016-5649 CRITICAL

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

Jul 24, 2018 2 affected product(s) NVD
9.8
CVSS
27.2%
EPSS
⚡ 47.4
CVE-2018-5064 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
25.4%
EPSS
⚡ 46.8
CVE-2018-5069 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
25.4%
EPSS
⚡ 46.8
CVE-2018-5070 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
25.4%
EPSS
⚡ 46.8
CVE-2018-12798 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
13.5%
EPSS
⚡ 43.2
CVE-2018-12804 CRITICAL

Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking.

Jul 20, 2018 1 affected product(s) NVD
9.8
CVSS
11.5%
EPSS
⚡ 42.6
CVE-2018-12815 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
11.0%
EPSS
⚡ 42.5
CVE-2018-12802 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Security Bypass vulnerability. Successful exploitation could lead to privilege escalation.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.8%
EPSS
⚡ 41.9
CVE-2018-12792 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2018-12812 CRITICAL

Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.6%
EPSS
⚡ 41.8
CVE-2018-5009 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2018-5011 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.7%
EPSS
⚡ 41.8
CVE-2018-5021 CRITICAL

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

Jul 20, 2018 6 affected product(s) NVD
9.8
CVSS
8.5%
EPSS
⚡ 41.7
CVE-2018-12805 CRITICAL

Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation.

Jul 20, 2018 1 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2018-1999019 CRITICAL

Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears to have been fixed in After commit 0de84700648f098c1fbf6b807dee28ec640efe62.

Jul 23, 2018 20 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2018-1999010 CRITICAL

FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in cced03dd667a5df6df8fd40d8de0bff477ee02e8 and later.

Jul 23, 2018 2 affected product(s) NVD
9.8
CVSS
3.1%
EPSS
⚡ 40.1
CVE-2017-14444 CRITICAL

An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly handles the URL parameter during a firmware update request, leading to a buffer overflow on a global section. An attacker can send an HTTP GET request to trigger this vulnerability.

Aug 2, 2018 1 affected product(s) NVD
9.9
CVSS
1.4%
EPSS
⚡ 40
CVE-2017-14446 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation unsafely extracts parameters from the query string, leading to a buffer overflow on the stack. An attacker can send an HTTP GET request to trigger this vulnerability.

Aug 2, 2018 1 affected product(s) NVD
9.9
CVSS
1.3%
EPSS
⚡ 40
CVE-2017-16338 CRITICAL

An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bad0 the value for the host key is copied using strcpy to the buffer at 0xa00016e0. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

Aug 2, 2018 1 affected product(s) NVD
9.9
CVSS
1.4%
EPSS
⚡ 40