Nomisec Exploits

23,093 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-14287 NOMISEC HIGH
Sudo <1.8.28 - Privilege Escalation
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
by n0w4n
12 stars
CVSS 8.8
CVE-2019-16920 NOMISEC CRITICAL
D-Link DIR-655 Firmware < 3.02b05 - Unauthenticated Remote Code Execution via PingTest CGI
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
by eniac888
1 stars
CVSS 9.8
CVE-2019-8781 NOMISEC HIGH
macOS < 10.15 - Out-of-bounds Write
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.
by A2nkF
293 stars
CVSS 7.8
CVE-2018-11770 NOMISEC MEDIUM
Apache Spark 1.3.0-2.3.3 - Unauthenticated Job Submission via REST API
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests to submit jobs via spark-submit. However, the REST API does not use this or any other authentication mechanism, and this is not adequately documented. In this case, a user would be able to run a driver program without authenticating, but not launch executors, using the REST API. This REST API is also used by Mesos, when set up to run in cluster mode (i.e., when also running MesosClusterDispatcher), for job submission. Future versions of Spark will improve documentation on these points, and prohibit setting 'spark.authenticate.secret' when running the REST APIs, to make this clear. Future versions will also disable the REST API by default in the standalone master by changing the default value of 'spark.master.rest.enabled' to 'false'.
by ivanitlearning
1 stars
CVSS 4.2
CVE-2019-16279 NOMISEC HIGH
nostromo nhttpd < 1.9.6 - Denial of Service via SSL_accept Memory Error
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
by ianxtianxt
CVSS 7.5
CVE-2019-16278 NOMISEC CRITICAL
nostromo_nhttpd <= 1.9.6 - Remote Code Execution via Directory Traversal in http_verify
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
by imjdl
9 stars
CVSS 9.8
CVE-2018-8389 NOMISEC HIGH
Internet Explorer <11 - Memory Corruption
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390.
by sandi-go
CVSS 7.5
CVE-2018-12798 NOMISEC CRITICAL
Adobe Acrobat and Reader <2018.011.20040 - RCE
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
by sandi-go
CVSS 9.8
CVE-2018-9951 NOMISEC HIGH
Foxit Reader < 9.0.1.1049 - Remote Code Execution via CPDF_Object Use-After-Free
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CPDF_Object objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5414.
by sandi-go
CVSS 8.8
CVE-2018-14442 NOMISEC CRITICAL
Foxit Reader <9.2 - PhantomPDF <9.2 - Use After Free
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
by sandi-go
CVSS 9.8
CVE-2019-14287 NOMISEC HIGH
Sudo <1.8.28 - Privilege Escalation
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
by FauxFaux
1 stars
CVSS 8.8
CVE-2018-9950 NOMISEC MEDIUM
Foxit Reader and PhantomPDF < 9.0.1.1049 - Out-of-bounds Read in PDF Parser
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5413.
by sandi-go
CVSS 6.5
CVE-2018-15968 NOMISEC MEDIUM
Adobe Acrobat DC < 15.006.30452, 15.008.20082-18.011.20063 - Out-of-bounds Read
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
by sandi-go
CVSS 5.5
CVE-2019-16278 NOMISEC CRITICAL
nostromo_nhttpd <= 1.9.6 - Remote Code Execution via Directory Traversal in http_verify
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
by jas502n
70 stars
CVSS 9.8
CVE-2019-2215 NOMISEC HIGH
Android Binder Use-After-Free Exploit
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
by kangtastic
126 stars
CVSS 7.8
CVE-2017-14948 NOMISEC CRITICAL
D-Link DIR-868L/880L/885L/890L/895L/895R Firmware - Remote Code Execution via CONTENT_TYPE Header Buffer Overflow
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.
by badnack
3 stars
CVSS 9.8
CVE-2019-14529 NOMISEC CRITICAL
OpenEMR < 5.0.2 - SQL Injection via eye_mag/save.php
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
by Wezery
CVSS 9.8
CVE-2019-3778 NOMISEC MEDIUM
Spring Security OAuth < 2.0.17 - Open Redirect via Authorization Endpoint
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the "redirect_uri" parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code. This vulnerability exposes applications that meet all of the following requirements: Act in the role of an Authorization Server (e.g. @EnableAuthorizationServer) and uses the DefaultRedirectResolver in the AuthorizationEndpoint. This vulnerability does not expose applications that: Act in the role of an Authorization Server and uses a different RedirectResolver implementation other than DefaultRedirectResolver, act in the role of a Resource Server only (e.g. @EnableResourceServer), act in the role of a Client only (e.g. @EnableOAuthClient).
by BBB-man
CVSS 6.5
CVE-2019-16759 NOMISEC CRITICAL
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
by FarjaalAhmad
4 stars
CVSS 9.8
CVE-2019-0708 NOMISEC CRITICAL
CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
by Ameg-yag
CVSS 9.8
CVE-2019-16692 NOMISEC CRITICAL
phpipam < 1.4 - SQL Injection via Custom Fields Filter Table Parameter
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
by kkirsche
5 stars
CVSS 9.8
CVE-2019-17124 NOMISEC CRITICAL
Kramer VIAware 2.5.0719.1034 - Incorrect Access Control
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
by hessandrew
2 stars
CVSS 9.8
CVE-2018-7600 NOMISEC CRITICAL
Drupal Drupalgeddon 2 Forms API Property Injection
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
by shellord
1 stars
CVSS 9.8
CVE-2019-15846 NOMISEC CRITICAL
Exim < 4.92.2 - Remote Code Execution via Trailing Backslash
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
by synacktiv
30 stars
CVSS 9.8
CVE-2018-6789 NOMISEC CRITICAL
Exim < 4.90.1 - Remote Code Execution via base64d Buffer Overflow
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
by synacktiv
9 stars
CVSS 9.8