Vulnerabilidades em N/A

160.181 resultados
CVE-2022-36267In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionEPSS 54.5%CVE-2019-16667diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. ThisEPSS 54.5%CVE-2009-1730Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary EPSS 54.5%CVE-2016-2056xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacterEPSS 54.5%CVE-2018-20323www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.EPSS 54.5%CVE-2018-20247In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree EPSS 54.5%CVE-2005-4734Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remoEPSS 54.5%CVE-2002-0371Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackeEPSS 54.4%CVE-2007-3040Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary cEPSS 54.4%CVE-2021-36356KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts aEPSS 54.4%CVE-2017-14849Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pEPSS 54.4%CVE-2005-0068The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to fEPSS 54.4%CVE-2001-1217Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitiveEPSS 54.4%CVE-2011-0027Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory alEPSS 54.4%CVE-2020-29557CRITICALAn issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackerEPSS 54.3%KEVCVE-2013-1899Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to caEPSS 54.3%CVE-2019-6453mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify EPSS 54.3%CVE-1999-0661A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers EPSS 54.2%CVE-2006-5229OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attaEPSS 54.2%CVE-2018-5347Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.pEPSS 54.2%