Total
10067 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-1581 | 1 Paloaltonetworks | 1 Pan-os | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4. | |||||
CVE-2018-11686 | 1 Flowpaper | 1 Flexpaper | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | |||||
CVE-2019-1716 | 1 Cisco | 10 Ip Conference Phone 7800, Ip Conference Phone 7800 Firmware, Ip Phone 8800 and 7 more | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code. The vulnerability exists because the software improperly validates user-supplied input during user authentication. An attacker could exploit this vulnerability by connecting to an affected device using HTTP and supplying malicious user credentials. A successful exploit could allow the attacker to trigger a reload of an affected device, resulting in a DoS condition, or to execute arbitrary code with the privileges of the app user. Cisco fixed this vulnerability in the following SIP Software releases: 10.3(1)SR5 and later for Cisco Unified IP Conference Phone 8831; 11.0(4)SR3 and later for Cisco Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 and later for the rest of the Cisco IP Phone 7800 Series and 8800 Series. | |||||
CVE-2016-10824 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 9.3 HIGH | 9.8 CRITICAL |
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90). | |||||
CVE-2014-10384 | 1 Memphis Documents Library Project | 1 Memphis Documents Library | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion. | |||||
CVE-2018-4406 | 1 Apple | 1 Mac Os X | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
A denial of service issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14. | |||||
CVE-2019-1826 | 1 Cisco | 12 Aironet 1562d, Aironet 1562e, Aironet 1562i and 9 more | 2024-02-04 | 5.5 MEDIUM | 5.7 MEDIUM |
A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation on QoS fields within Wi-Fi frames by the affected device. An attacker could exploit this vulnerability by sending malformed Wi-Fi frames to an affected device. A successful exploit could allow the attacker to cause the affected device to crash, resulting in a DoS condition. | |||||
CVE-2018-4054 | 1 Pixar | 1 Renderman | 2024-02-04 | 7.2 HIGH | 7.8 HIGH |
A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman, version 22.2.0. A user with local access can use this vulnerability to escalate their privileges to root. An attacker would need local access to the machine to successfully exploit this flaw. | |||||
CVE-2019-10742 | 1 Axios | 1 Axios | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded. | |||||
CVE-2017-18461 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 5.0 MEDIUM | 4.3 MEDIUM |
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223). | |||||
CVE-2017-18410 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284). | |||||
CVE-2019-5839 | 4 Debian, Fedoraproject, Google and 1 more | 5 Debian Linux, Fedora, Chrome and 2 more | 2024-02-04 | 4.3 MEDIUM | 4.3 MEDIUM |
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL. | |||||
CVE-2019-9717 | 1 Libav | 1 Libav | 2024-02-04 | 7.1 HIGH | 6.5 MEDIUM |
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf. | |||||
CVE-2018-4274 | 1 Apple | 2 Iphone Os, Safari | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2. | |||||
CVE-2019-1302 | 1 Microsoft | 1 Asp.net Core | 2024-02-04 | 6.8 MEDIUM | 8.8 HIGH |
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'. | |||||
CVE-2019-16370 | 1 Gradle | 1 Gradle | 2024-02-04 | 4.3 MEDIUM | 5.9 MEDIUM |
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900. | |||||
CVE-2018-19580 | 1 Gitlab | 1 Gitlab | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made. | |||||
CVE-2018-12219 | 1 Intel | 1 Graphics Driver | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to read memory via local access via local access. | |||||
CVE-2017-18434 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 7.2 HIGH | 7.8 HIGH |
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237). | |||||
CVE-2019-9831 | 1 Airmore | 1 Airmore | 2024-02-04 | 7.8 HIGH | 7.5 HIGH |
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via many simultaneous /?Key=PhoneRequestAuthorization requests. |