CSV
14,854 results for "vulnerability" Page 97
CVE-2019-0547 CRITICAL Exploit

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.

Jan 8, 2019 1 affected product(s) NVD
9.8
CVSS
71.4%
EPSS
⚡ 70.6
CVE-2019-6339 CRITICAL

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

Jan 22, 2019 5 affected product(s) NVD
9.8
CVSS
33.2%
EPSS
⚡ 49.2
CVE-2019-0586 CRITICAL

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

Jan 8, 2019 3 affected product(s) NVD
9.8
CVSS
15.4%
EPSS
⚡ 43.8
CVE-2019-7297 CRITICAL

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.

Jan 31, 2019 1 affected product(s) NVD
9.8
CVSS
12.5%
EPSS
⚡ 42.9
CVE-2018-19716 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
9.7%
EPSS
⚡ 42.1
CVE-2018-19698 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2018-19700 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
6.2%
EPSS
⚡ 41.1
CVE-2018-16036 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-16037 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-16039 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-16040 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-19702 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.6%
EPSS
⚡ 40.9
CVE-2018-19707 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-19708 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2018-19715 CRITICAL

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Jan 18, 2019 12 affected product(s) NVD
9.8
CVSS
5.7%
EPSS
⚡ 40.9
CVE-2019-0006 CRITICAL

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can result in a crash of the fxpc daemon or may potentially lead to remote code execution. This issue only occurs when the crafted packet it destined to the device. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D47 on EX and QFX Virtual Chassis Platforms; 15.1 versions prior to 15.1R7-S3 all Virtual Chassis Platforms 15.1X53 versions prior to 15.1X53-D50 on EX and QFX Virtual Chassis Platforms.

Jan 15, 2019 26 affected product(s) NVD
9.8
CVSS
5.3%
EPSS
⚡ 40.8
CVE-2018-13045 CRITICAL

SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.

Jan 2, 2019 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2018-6444 CRITICAL

A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands.

Jan 22, 2019 2 affected product(s) NVD
9.8
CVSS
3.3%
EPSS
⚡ 40.2
CVE-2019-6798 CRITICAL

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.

Jan 26, 2019 1 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.2
CVE-2018-20749 CRITICAL

LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Jan 30, 2019 14 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2