9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7755
dat.gui General
7.5
HIGH
EPSS
0.6%
2020 1 PoC

All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.

CVE-2020-7753
trim General
7.5
HIGH
EPSS
4.0%
2020 2 PoCs

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

CVE-2016-6321
Software Genérico General
7.5
HIGH
EPSS
11.1%
2016 3 PoCs

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.

CVE-2016-8332
OPENJPEG General
7.5
HIGH
EPSS
1.2%
2016 1 PoC

A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out of bound heap write resulting in heap corruption leading to arbitrary code execution. For a successful attack, the target user needs to open a malicious jpeg2000 file. The jpeg2000 image file format is mostly used for embedding images inside PDF documents and the OpenJpeg library is used by a number of popular PDF ren

CVE-2016-20015
Software Genérico General
7.5
HIGH
EPSS
0.3%
2016 1 PoC

In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.

CVE-2016-9049
Database Server General
7.5
HIGH
EPSS
1.4%
2016 2 PoCs

An exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server process to dereference a null pointer. An attacker can simply connect to a TCP port in order to trigger this vulnerability.

CVE-2016-3976
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
76.3%
2016 5 PoCs

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.

CVE-2016-8714
R General
7.5
HIGH
EPSS
0.8%
2016 1 PoC

An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability.

CVE-2016-9036
Msgpuck library General
7.5
HIGH
EPSS
1.3%
2016 CWE-125 2 PoCs

An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.

CVE-2016-3627
Software Genérico General
7.5
HIGH
EPSS
0.2%
2016 4 PoCs

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.

CVE-2016-6301
Software Genérico General
7.5
HIGH
EPSS
3.3%
2016 8 PoCs

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.

CVE-2016-9037
Tarantool General
7.5
HIGH
EPSS
2.8%
2016 CWE-125 1 PoC

An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the specified key's value. This can lead to an out of bounds read within the context of the server. An attacker who exploits this vulnerability can cause a denial of service vulnerability on the server.

CVE-2016-0189
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
90.8%
2016 3 PoCs

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

CVE-2018-6662
McAfee Management of Native Encryption (MNE) General
7.5
HIGH
EPSS
0.0%
2018 1 PoC

Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a crafted user input.

CVE-2018-3975
Atlantis Word Processor General
7.5
HIGH
EPSS
0.6%
2018 1 PoC

An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds write, which in turn could lead to code execution.

CVE-2018-19591
Software Genérico General
7.5
HIGH
EPSS
1.8%
2018 1 PoC

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

CVE-2018-1084
corosync General
7.5
HIGH
EPSS
0.3%
2018 CWE-190 1 PoC

corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.

CVE-2018-8298
🔥 KEV ChakraCore General
7.5
HIGH
EPSS
89.4%
2018 1 PoC

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8291, CVE-2018-8296.

CVE-2018-20679
Software Genérico General
7.5
HIGH
EPSS
11.8%
2018 3 PoCs

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.

CVE-2018-17559
Software Genérico General
7.5
HIGH
EPSS
0.2%
2018 1 PoC

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.