Vulnerabilities > Exposed Dangerous Method or Function

DATE CVE VULNERABILITY TITLE RISK
2019-07-29 CVE-2019-12948 Exposed Dangerous Method or Function vulnerability in Polycom Unified Communications Software
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
network
low complexity
polycom CWE-749
8.3
2019-07-01 CVE-2019-4386 Exposed Dangerous Method or Function vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash.
network
low complexity
ibm CWE-749
6.5
2018-12-21 CVE-2018-19322 Exposed Dangerous Method or Function vulnerability in Gigabyte products
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports.
local
low complexity
gigabyte CWE-749
7.8
2018-03-23 CVE-2018-8949 Exposed Dangerous Method or Function vulnerability in Misp-Project Misp
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89.
network
low complexity
misp-project CWE-749
4.3
2017-11-22 CVE-2017-2735 Exposed Dangerous Method or Function vulnerability in Huawei Y6 PRO Firmware 9.1.0.248(C636E5R3P1)
TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability.
local
low complexity
huawei CWE-749
7.1
2016-12-29 CVE-2016-7462 Exposed Dangerous Method or Function vulnerability in VMWare Vrealize Operations
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
network
low complexity
vmware CWE-749
8.5