Sitelet https://web.archive.org/web/20200202122641/https://nvd.nist.gov/

National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database



The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.
 
Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2019-17095 — A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading... read CVE-2019-17095
    Published: January 27, 2020; 01:15:12 PM -05:00

    V3.1: 9.8 CRITICAL
        V2: 10.0 HIGH

  • CVE-2019-17099 — An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecur... read CVE-2019-17099
    Published: January 27, 2020; 01:15:12 PM -05:00

    V3.1: 7.8 HIGH
        V2: 4.4 MEDIUM

  • CVE-2020-7908 — In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
    Published: January 30, 2020; 01:15:11 PM -05:00

    V3.1: 4.3 MEDIUM
        V2: 4.3 MEDIUM

  • CVE-2020-7909 — In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
    Published: January 30, 2020; 01:15:11 PM -05:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2020-7912 — In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
    Published: January 30, 2020; 01:15:12 PM -05:00

    V3.1: 5.3 MEDIUM
        V2: 5.0 MEDIUM

  • CVE-2013-2567 — An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.
    Published: January 29, 2020; 12:15:11 PM -05:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2013-2568 — A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.
    Published: January 29, 2020; 01:15:11 PM -05:00

    V3.1: 9.8 CRITICAL
        V2: 10.0 HIGH

  • CVE-2013-2569 — A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.
    Published: January 29, 2020; 01:15:11 PM -05:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2013-2570 — A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.
    Published: January 29, 2020; 01:15:11 PM -05:00

    V3.1: 9.8 CRITICAL
        V2: 7.5 HIGH

  • CVE-2012-6302 — Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
    Published: January 24, 2020; 10:15:13 AM -05:00

    V3.1: 7.8 HIGH
        V2: 7.2 HIGH

  • CVE-2013-4333 — OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
    Published: January 24, 2020; 10:15:13 AM -05:00

    V3.1: 9.1 CRITICAL
        V2: 6.4 MEDIUM

  • CVE-2015-4041 — The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (... read CVE-2015-4041
    Published: January 24, 2020; 12:15:12 PM -05:00

    V3.1: 7.8 HIGH
        V2: 4.6 MEDIUM

  • CVE-2015-4042 — Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.
    Published: January 24, 2020; 12:15:12 PM -05:00

    V3.1: 9.8 CRITICAL
        V2: 7.5 HIGH

  • CVE-2015-2929 — The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
    Published: January 24, 2020; 01:15:12 PM -05:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2020-8315 — In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's c... read CVE-2020-8315
    Published: January 28, 2020; 02:15:17 PM -05:00

    V3.1: 5.5 MEDIUM
        V2: 4.3 MEDIUM

  • CVE-2013-3316 — Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
    Published: January 29, 2020; 05:15:11 PM -05:00

    V3.1: 9.8 CRITICAL
        V2: 10.0 HIGH

  • CVE-2013-3317 — Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
    Published: January 29, 2020; 05:15:11 PM -05:00

    V3.1: 9.8 CRITICAL
        V2: 10.0 HIGH

  • CVE-2020-8442 — In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.
    Published: January 29, 2020; 08:15:10 PM -05:00

    V3.1: 8.8 HIGH
        V2: 6.5 MEDIUM

  • CVE-2020-8446 — In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local use... read CVE-2020-8446
    Published: January 29, 2020; 08:15:10 PM -05:00

    V3.1: 5.5 MEDIUM
        V2: 2.1 LOW

  • CVE-2020-8448 — In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written directly to the analysisd UNIX domain socket by a local... read CVE-2020-8448
    Published: January 29, 2020; 08:15:11 PM -05:00

    V3.1: 5.5 MEDIUM
        V2: 2.1 LOW