1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2017-16867
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.8%
2017 2 PoCs

Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a camera and enter a house if a delivery driver failed to ensure a locked door before leaving.

CVE-2014-0229
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

CVE-2015-2667
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Untrusted search path vulnerability in GNS3 1.2.3 allows local users to gain privileges via a Trojan horse uuid.dll in an unspecified directory.

CVE-2017-0893
Nextcloud Server Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2017 CWE-79 1 PoC

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVE-2019-18295
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
2.0%
2019 CWE-122 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18293, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE-2017-6550
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
5.9%
2017 3 PoCs

Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.

CVE-2017-7040
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
3.5%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-0895
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2017 CWE-285 1 PoC

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVE-2004-2067
Software Genérico Web Database Cloud
N/A
UNKNOWN
EPSS
1.6%
2004 1 PoC

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

CVE-2019-5160
WAGO PFC200 Firmware Web Cloud
N/A
UNKNOWN
EPSS
2.2%
2019 1 PoC

An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker controlled Azure IoT Hub node.

CVE-2004-0253
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.5%
2004 1 PoC

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.

CVE-2004-0278
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2004 1 PoC

Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.

CVE-2019-3998
SimpliSafe SS3 Base Station Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to.

CVE-2012-1844
Software Genérico Cloud
N/A
UNKNOWN
EPSS
2.3%
2012 4 PoCs

The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier for remote attackers to obtain access via unknown vectors.

CVE-2012-2270
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
15.8%
2012 1 PoC

Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

CVE-2019-9584
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.

CVE-2012-2230
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.

CVE-2019-7181
myQNAPcloud Connect Cloud
N/A
UNKNOWN
EPSS
12.9%
2019 2 PoCs

Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.

CVE-2012-1035
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.6%
2012 1 PoC

AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVE-2012-0785
Jenkins DevOps Cloud
N/A
UNKNOWN
EPSS
1.9%
2012 1 PoC

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."