CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 41323 CVEs

CVE ID Severity Description EPSS Published
7.5 HIGH

dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name.

3.4% 2017-04-10
7.5 HIGH

Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.

12.3% 2017-04-10
7.5 HIGH

NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.

1.7% 2017-04-10
7.5 HIGH

The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.

0.6% 2017-04-10
7.5 HIGH

botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a certificate with a loop in the certificate chain.

1.0% 2017-04-10
7.5 HIGH

botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle attack against TLS CBC ciphersuites.

1.7% 2017-04-10
7.5 HIGH

In ImageMagick 7.0.4-9, an infinite loop can occur because of a floating-point rounding error in some of the color algorithms. This affects ModulateHSL, ModulateHCL, ModulateHCLp, ModulateHSB, ModulateHSI, ModulateHSV, ModulateHWB, ModulateLCHab, and ModulateLCHuv.

1.5% 2017-04-10
7.5 HIGH

crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.

4.3% 2017-04-10
8.8 HIGH

Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.

6.2% 2017-04-10
7.5 HIGH

Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.

15.8% 2017-04-10
7.5 HIGH

Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

1.4% 2017-04-10
7.5 HIGH

In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allows context-dependent attackers to obtain sensitive information by reading the .xml dotfile.

1.2% 2017-04-10
7.5 HIGH

Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.

1.3% 2017-04-10
7.5 HIGH

CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.def.

1.4% 2017-04-10
8.8 HIGH

OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9.

1.9% 2017-04-10
8.8 HIGH

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.

1.7% 2017-04-10
8.8 HIGH

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection.

3.6% 2017-04-10
7.5 HIGH

OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.

1.1% 2017-04-10
7.5 HIGH

OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.

1.2% 2017-04-10
7.5 HIGH

OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.

0.9% 2017-04-10
7.5 HIGH

OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.

1.1% 2017-04-10
7.5 HIGH

OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.

1.1% 2017-04-10
7.5 HIGH

OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.

1.4% 2017-04-10
8.8 HIGH

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

0.7% 2017-04-10
8.8 HIGH

OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.

2.3% 2017-04-10
7.5 HIGH

AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."

8.8% 2017-04-10
8.8 HIGH

AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.

2.2% 2017-04-10
8.8 HIGH

Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.

2.0% 2017-04-10
7.8 HIGH

Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.

1.1% 2017-04-10
7.5 HIGH

Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.

1.2% 2017-04-10
7.5 HIGH

The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.

1.2% 2017-04-10
7.8 HIGH

Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.

0.3% 2017-04-10
8.8 HIGH

Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

1.1% 2017-04-10
8.8 HIGH

Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a Settings URL.

1.7% 2017-04-10
7.5 HIGH

iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.

1.3% 2017-04-10
7.5 HIGH

Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics.net URLs, stream.m3u8 URIs, and cam_service_enable.cgi.

1.5% 2017-04-10
8.8 HIGH

TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.

1.2% 2017-04-10
7.5 HIGH

Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.

1.1% 2017-04-10
7.8 HIGH

aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.

1.5% 2017-04-09
7.8 HIGH

au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.

1.5% 2017-04-09
7.8 HIGH

au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.

1.5% 2017-04-09
7.8 HIGH

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

2.6% 2017-04-09
7.8 HIGH

LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

2.5% 2017-04-09
7.8 HIGH

LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

1.5% 2017-04-09
7.8 HIGH

LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

2.0% 2017-04-09
7.8 HIGH

tif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.

2.5% 2017-04-09
7.8 HIGH

tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

1.8% 2017-04-09
7.8 HIGH

LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

1.9% 2017-04-09
7.8 HIGH

The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

2.0% 2017-04-09
7.8 HIGH

A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.

1.3% 2017-04-07