1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2017-8228
Software Genérico Cloud
N/A
UNKNOWN
EPSS
2.3%
2017 1 PoC

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that the user actually owns the camera other than knowing the serial number of the camera. This can allow an attacker who knows the serial number to easily add another user's camera to an attacker's cloud account and control it completely. This is possible in case of any camera that is currently not a part of an Amcrest cloud account or has been removed from the

CVE-2017-16886
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

CVE-2017-0894
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.8%
2017 CWE-285 1 PoC

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVE-2017-17440
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2017 5 PoCs

GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.

CVE-2014-5640
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The CM Backup -Restore,Cloud,Photo (aka com.ijinshan.kbackup) application 1.1.0.135 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-8357
Software Genérico Cloud
N/A
UNKNOWN
EPSS
18.3%
2014 2 PoCs

backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.

CVE-2015-4078
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

CVE-2017-7645
Software Genérico Cloud
N/A
UNKNOWN
EPSS
16.0%
2017 2 PoCs

The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.

CVE-2017-7048
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
4.4%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-16887
Software Genérico Cloud
N/A
UNKNOWN
EPSS
4.0%
2017 1 PoC

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.

CVE-2017-7037
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
3.5%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-0891
Nextcloud Server Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2017 CWE-79 1 PoC

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVE-2017-18263
Software Genérico Cloud
N/A
UNKNOWN
EPSS
5.6%
2017 2 PoCs

Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.

CVE-2017-10232
Hospitality WebSuite8 Cloud Service Web Database Cloud
N/A
UNKNOWN
EPSS
0.7%
2017 1 PoC

Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality WebSuite8 Cloud Service accessible data as well as unauthorized update, insert or delete access to some of Hospitality WebSuite8 Cloud Servi

CVE-2017-9450
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory.

CVE-2017-13802
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
21.4%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-0888
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.5%
2017 CWE-451 1 PoC

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.

CVE-2017-10064
Hospitality WebSuite8 Cloud Service Web Database Cloud
N/A
UNKNOWN
EPSS
0.5%
2017 1 PoC

Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hospitality WebSuite8 Cloud Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauth

CVE-2014-6904
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-0285
Software Genérico Cloud
N/A
UNKNOWN
EPSS
8.5%
2015 8 PoCs

The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and then conducting a brute-force attack.