İçeriğe atla
Noroxi

CWE-254 · 379 kayıt

7PK - Security Features

Bu sınıftaki CVE’ler

379 kayıt

  • CVE-2016-2296
    56Planlayın

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows rem

    KritikCVSS 9,4SilahlaştırılmışEPSS %64

    meteocontrol · web\'log basic 10014 May 2016

  • CVE-2015-1158
    49Planlayın

    The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-

    KritikCVSS 10,0Kavram kanıtıEPSS %30

    cups · cups26 Haz 2015

  • CVE-2016-0161
    47Planlayın

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege

    OrtaCVSS 6,5İstismar yokEPSS %69

    microsoft · edge12 Nis 2016

  • CVE-2015-1793
    45Planlayın

    The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic

    OrtaCVSS 6,5SilahlaştırılmışEPSS %62

    openssl · openssl9 Tem 2015

  • CVE-2016-3238
    43Planlayın

    The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201

    YüksekCVSS 8,1Kavram kanıtıEPSS %35

    microsoft · windows 1012 Tem 2016

  • CVE-2016-2118
    41Planlayın

    The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DC

    YüksekCVSS 7,5Kavram kanıtıEPSS %37

    samba · samba12 Nis 2016

  • CVE-2016-10178
    41Planlayın

    An issue was discovered on the D-Link DWR-932B router.

    KritikCVSS 9,8İstismar yokEPSS %7

    dlink · dwr-932b firmware30 Oca 2017

  • CVE-2016-6957
    41Planlayın

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Contin

    KritikCVSS 9,8İstismar yokEPSS %6

    adobe · acrobat13 Eki 2016

  • CVE-2016-4215
    41Planlayın

    Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Contin

    KritikCVSS 9,8İstismar yokEPSS %6

    adobe · acrobat12 Tem 2016

  • CVE-2014-5334
    41Planlayın

    FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.

    KritikCVSS 9,8İstismar yokEPSS %5

    freenas · freenas8 Oca 2018

  • CVE-2015-3972
    41Planlayın

    The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easie

    KritikCVSS 10,0İstismar yokEPSS %3

    janitza · umg 50828 Eki 2015

  • CVE-2016-5788
    41Planlayın

    General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it

    KritikCVSS 10,0İstismar yokEPSS %2

    ge · bently nevada 3500\/22m usb firmware24 Kas 2016

  • CVE-2015-8286
    40Planlayın

    Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP por

    KritikCVSS 9,8İstismar yokEPSS %5

    zhuhai · raysharp firmware18 Şub 2016

  • CVE-2015-8803
    40Planlayın

    The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its

    KritikCVSS 9,8İstismar yokEPSS %4

    nettle project · nettle23 Şub 2016

  • CVE-2015-7554
    40Planlayın

    The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or

    KritikCVSS 9,8İstismar yokEPSS %4

    libtiff · libtiff8 Oca 2016

  • CVE-2017-8227
    40Planlayın

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are de

    KritikCVSS 9,8İstismar yokEPSS %4

    amcrest · ipm-721s firmware3 Tem 2019

  • CVE-2015-8804
    40Planlayın

    x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation

    KritikCVSS 9,8İstismar yokEPSS %4

    nettle project · nettle23 Şub 2016

  • CVE-2015-8857
    40Planlayın

    The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which m

    KritikCVSS 9,8İstismar yokEPSS %4

    uglifyjs project · uglifyjs23 Oca 2017

  • CVE-2015-6473
    40Planlayın

    WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.

    KritikCVSS 9,8İstismar yokEPSS %4

    wago · 750-849 firmware22 Ağu 2017

  • CVE-2016-1896
    40Planlayın

    Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0

    KritikCVSS 9,8İstismar yokEPSS %3

    lexmark · printer firmware27 Oca 2016

  • CVE-2016-6629
    40Planlayın

    An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive.

    KritikCVSS 9,8İstismar yokEPSS %3

    phpmyadmin · phpmyadmin10 Ara 2016

  • CVE-2011-4889
    40Planlayın

    The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before

    KritikCVSS 9,8İstismar yokEPSS %3

    ibm · websphere application server8 Şub 2018

  • CVE-2016-10321
    40Planlayın

    web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for

    KritikCVSS 9,8İstismar yokEPSS %3

    web2py · web2py10 Nis 2017

  • CVE-2016-0332
    40Planlayın

    IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed l

    KritikCVSS 9,8İstismar yokEPSS %2

    ibm · security identity manager virtual appliance12 Oca 2018

  • CVE-2016-9865
    40Planlayın

    An issue was discovered in phpMyAdmin.

    KritikCVSS 9,8İstismar yokEPSS %2

    phpmyadmin · phpmyadmin10 Ara 2016

Tüm zafiyet sınıfları