CSV
14,738 results for "vulnerability" Page 85
CVE-2018-13415 CRITICAL

In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Plex, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Aug 13, 2018 1 affected product(s) NVD
9.8
CVSS
31.8%
EPSS
⚡ 48.7
CVE-2018-8273 CRITICAL

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

Aug 15, 2018 3 affected product(s) NVD
9.8
CVSS
29.2%
EPSS
⚡ 48
CVE-2018-8302 CRITICAL

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

Aug 15, 2018 5 affected product(s) NVD
9.8
CVSS
25.5%
EPSS
⚡ 46.9
CVE-2018-13417 CRITICAL

In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Vuze, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

Aug 13, 2018 1 affected product(s) NVD
9.8
CVSS
20.7%
EPSS
⚡ 45.4
CVE-2018-15152 CRITICAL

Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.

Aug 15, 2018 1 affected product(s) NVD
9.1
CVSS
25.9%
EPSS
⚡ 44.2
CVE-2018-1000226 CRITICAL

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vulnerability in XMLRPC API (/cobbler_api) that can result in Privilege escalation, data manipulation or exfiltration, LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.

Aug 20, 2018 1 affected product(s) NVD
9.8
CVSS
12.5%
EPSS
⚡ 42.9
CVE-2018-11511 CRITICAL

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

Aug 16, 2018 1 affected product(s) NVD
9.8
CVSS
11.2%
EPSS
⚡ 42.6
CVE-2018-10510 CRITICAL

A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.

Aug 15, 2018 2 affected product(s) NVD
9.8
CVSS
6.5%
EPSS
⚡ 41.1
CVE-2018-6692 CRITICAL

Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet.

Aug 21, 2018 1 affected product(s) NVD
10.0
CVSS
3.7%
EPSS
⚡ 41.1
CVE-2018-10511 CRITICAL

A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.

Aug 15, 2018 2 affected product(s) NVD
10.0
CVSS
2.7%
EPSS
⚡ 40.8
CVE-2018-1000644 CRITICAL

Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.

Aug 20, 2018 4 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2018-1000651 CRITICAL

Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted XML file.

Aug 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-1000652 CRITICAL

JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted MsBib file. This vulnerability appears to have been fixed in after commit 89f855d.

Aug 20, 2018 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2018-3856 CRITICAL

An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to trigger this vulnerability.

Aug 23, 2018 1 affected product(s) NVD
9.9
CVSS
3.4%
EPSS
⚡ 40.6
CVE-2018-3907 CRITICAL

An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'on_url' callback. An attacker can send an HTTP request to trigger this vulnerability.

Aug 24, 2018 1 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2018-7096 CRITICAL

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow code execution.

Aug 14, 2018 9 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2018-3867 CRITICAL

An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly handles the answer received from a smart camera, leading to a buffer overflow on the stack. An attacker can send a series of HTTP requests to trigger this vulnerability.

Aug 23, 2018 1 affected product(s) NVD
9.9
CVSS
2.0%
EPSS
⚡ 40.2
CVE-2018-3863 CRITICAL

On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. A strcpy overflows the destination buffer, which has a size of 40 bytes. An attacker can send an arbitrarily long "user" value in order to exploit this vulnerability.

Aug 23, 2018 1 affected product(s) NVD
9.9
CVSS
1.7%
EPSS
⚡ 40.1
CVE-2018-3878 CRITICAL

Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. A strncpy overflows the destination buffer, which has a size of 16 bytes. An attacker can send an arbitrarily long "region" value in order to exploit this vulnerability.

Aug 23, 2018 1 affected product(s) NVD
9.9
CVSS
1.5%
EPSS
⚡ 40.1
CVE-2018-3902 CRITICAL

An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts the URL field from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability.

Aug 23, 2018 1 affected product(s) NVD
9.9
CVSS
1.8%
EPSS
⚡ 40.1