1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2014-1226
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2014 1 PoC

The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.

CVE-2015-6024
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
49.3%
2015 4 PoCs

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.

CVE-2017-10128
Hospitality WebSuite8 Cloud Service Web Database Cloud
N/A
UNKNOWN
EPSS
0.5%
2017 1 PoC

Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hospitality WebSuite8 Cloud Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauth

CVE-2017-2479
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
24.7%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

CVE-2017-8221
Software Genérico Cloud
N/A
UNKNOWN
EPSS
19.1%
2017 2 PoCs

Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote attackers to obtain sensitive information by sniffing the network.

CVE-2017-13794
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
21.4%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2023-45992
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.6%
2023 3 PoCs

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

CVE-2017-6432
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which allows creation of fully privileged new users, in addition to capture of sensitive information.

CVE-2017-17560
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
83.4%
2017 2 PoCs

An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.

CVE-2017-0884
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2017 CWE-275 1 PoC

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVE-2017-13796
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
19.9%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2015-6500
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2015 1 PoC

Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.

CVE-2017-17587
Software Genérico Web Database Cloud
N/A
UNKNOWN
EPSS
2.4%
2017 2 PoCs

FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.

CVE-2017-0883
Nextcloud Server Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2017 CWE-275 1 PoC

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVE-2017-7895
Software Genérico Cloud
N/A
UNKNOWN
EPSS
21.5%
2017 1 PoC

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

CVE-2017-7117
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
9.1%
2017 2 PoCs

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-6506
Software Genérico Cloud
N/A
UNKNOWN
EPSS
21.6%
2017 2 PoCs

In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

CVE-2017-0890
Nextcloud Server Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2017 CWE-79 1 PoC

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

CVE-2017-7089
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
1.9%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.

CVE-2019-10677
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
5.5%
2019 3 PoCs

Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).