Last 20 Scored Vulnerability IDs & Summaries
CVSS Severity
-
CVE-2019-17095 —
A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading... read CVE-2019-17095
Published: January 27, 2020; 01:15:12 PM -05:00
-
CVE-2019-17099 —
An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecur... read CVE-2019-17099
Published: January 27, 2020; 01:15:12 PM -05:00
-
CVE-2020-7908 —
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
Published: January 30, 2020; 01:15:11 PM -05:00
-
CVE-2020-7909 —
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
Published: January 30, 2020; 01:15:11 PM -05:00
-
CVE-2020-7912 —
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
Published: January 30, 2020; 01:15:12 PM -05:00
-
CVE-2013-2567 —
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.
Published: January 29, 2020; 12:15:11 PM -05:00
-
CVE-2013-2568 —
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.
Published: January 29, 2020; 01:15:11 PM -05:00
-
CVE-2013-2569 —
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.
Published: January 29, 2020; 01:15:11 PM -05:00
-
CVE-2013-2570 —
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.
Published: January 29, 2020; 01:15:11 PM -05:00
-
CVE-2012-6302 —
Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
Published: January 24, 2020; 10:15:13 AM -05:00
-
CVE-2013-4333 —
OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
Published: January 24, 2020; 10:15:13 AM -05:00
-
CVE-2015-4041 —
The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (... read CVE-2015-4041
Published: January 24, 2020; 12:15:12 PM -05:00
-
CVE-2015-4042 —
Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.
Published: January 24, 2020; 12:15:12 PM -05:00
-
CVE-2015-2929 —
The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
Published: January 24, 2020; 01:15:12 PM -05:00
-
CVE-2020-8315 —
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's c... read CVE-2020-8315
Published: January 28, 2020; 02:15:17 PM -05:00
-
CVE-2013-3316 —
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
Published: January 29, 2020; 05:15:11 PM -05:00
-
CVE-2013-3317 —
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
Published: January 29, 2020; 05:15:11 PM -05:00
-
CVE-2020-8442 —
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.
Published: January 29, 2020; 08:15:10 PM -05:00
-
CVE-2020-8446 —
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local use... read CVE-2020-8446
Published: January 29, 2020; 08:15:10 PM -05:00
-
CVE-2020-8448 —
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written directly to the analysisd UNIX domain socket by a local... read CVE-2020-8448
Published: January 29, 2020; 08:15:11 PM -05:00