CVE-2018-8174 — Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
VulnWatch اطلاعات آسیبپذیری، امتیازها، نسخههای درگیر، راهکارها و دستورهای منتشرشده را از منابعی که در سامانه معرفی شدهاند گردآوری و برای دسترسی سادهتر نمایش میدهد. VulnWatch تولیدکننده یا مرجع اصلی این اطلاعات نیست.
ممکن است اطلاعات یک منبع ناقص، با تأخیر، تغییرکرده یا متناسب با محیط شما نباشد. VulnWatch صحت، کاملبودن، بهروز بودن یا نتیجه اجرای اطلاعات و دستورهای استخراجشده را تضمین نمیکند و مسئولیتی در قبال تصمیم، تغییر، اختلال یا خسارتی که صرفاً بر پایه این اطلاعات انجام شود نمیپذیرد.
پیش از نصب بهروزرسانی، اجرای دستور، تغییر تنظیمات یا هر اقدام عملیاتی، منبع اصلی را باز کنید، نسخه و محصول خود را تطبیق دهید، از اطلاعات مهم نسخه پشتیبان داشته باشید و تغییر را در محیط مناسب ارزیابی کنید.
آسیبپذیریها را بر اساس دستهبندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
A remote code execution vulnerability exists in Microsoft Office.
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
A code execution vulnerability exists in the Stapler web framework used by Jenkins
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
Intel products contain a vulnerability which can allow attackers to perform privilege escalation.
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.