CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 41401 CVEs

CVE ID Severity Description EPSS Published
7.5 HIGH

The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).

3.9% 2017-04-13
7.7 HIGH

Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).

5.6% 2017-04-13
7.5 HIGH

(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

6.9% 2017-04-13
7.5 HIGH

SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).

0.7% 2017-04-13
7.5 HIGH

In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS.

2.5% 2017-04-13
7.5 HIGH

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

1.5% 2017-04-13
7.5 HIGH

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.

1.5% 2017-04-13
7.8 HIGH

Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.

0.3% 2017-04-13
7.8 HIGH

Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.

2.1% 2017-04-13
8.8 HIGH

A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run arbitrary commands via unspecified vectors.

4.9% 2017-04-13
7.5 HIGH

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

11.3% 2017-04-13
8.8 HIGH

Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.

4.1% 2017-04-13
7.5 HIGH

Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.

0.7% 2017-04-13
7.8 HIGH

Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.

0.4% 2017-04-13
7.8 HIGH

Firejail does not properly clean environment variables, which allows local users to gain privileges.

0.4% 2017-04-13
7.8 HIGH

Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.

0.4% 2017-04-13
7.8 HIGH

Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.

0.4% 2017-04-13
7.8 HIGH

Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.

0.4% 2017-04-13
7.8 HIGH

Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

0.4% 2017-04-13
8.8 HIGH

SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.

4.2% 2017-04-13
7.5 HIGH

The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).

3.2% 2017-04-13
7.8 HIGH

Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

2.9% 2017-04-13
7.5 HIGH

InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).

1.9% 2017-04-13
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.

2.8% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.

2.5% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.

2.5% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.

2.5% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rpcrdma.c by correctly checking for going beyond the maximum offset.

2.7% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dof.c by using a different integer data type and adjusting a return value.

2.7% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.

3.3% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding length validation.

2.7% 2017-04-12
7.5 HIGH

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-bgp.c by using a different integer data type.

2.7% 2017-04-12
8.8 HIGH

An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.

2.7% 2017-04-12
8.8 HIGH

An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload.

4.3% 2017-04-12
7.5 HIGH

OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

2.9% 2017-04-12
7.0 HIGH

Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.

0.6% 2017-04-12
8.8 HIGH

Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

4.6% 2017-04-12
8.8 HIGH

SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.

2.0% 2017-04-12
8.8 HIGH

SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

1.6% 2017-04-12
8.8 HIGH

Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors.

1.0% 2017-04-12
8.8 HIGH

Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.

3.1% 2017-04-12
7.5 HIGH

Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.

5.2% 2017-04-12
7.8 HIGH

game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

2.3% 2017-04-12
7.8 HIGH

game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.

2.3% 2017-04-12
7.8 HIGH

Stack-based buffer overflow in game-music-emu before 0.6.1.

1.9% 2017-04-12
7.5 HIGH

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

2.7% 2017-04-12
8.8 HIGH

An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.

0.5% 2017-04-12
7.5 HIGH

An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.

0.8% 2017-04-12
7.8 HIGH

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the font manipulation functionality. Successful exploitation could lead to arbitrary code execution.

3.4% 2017-04-12
7.8 HIGH

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploitation could lead to arbitrary code execution.

13.5% 2017-04-12