1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2019-9156
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.

CVE-2019-15451
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Samsung J3 Android device with a build fingerprint of samsung/j3y17ltedx/j3y17lte:8.0.0/R16NW/J330GDXS3BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=6010000, versionName=6.1.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

CVE-2014-5791
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Daum Cloud (aka net.daum.android.cloud) application 1.6.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-4699
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in the Splash Portal in Cloud4Wi before 5.9.7 allows remote attackers to inject arbitrary web script or HTML via the recoveryMessage parameter to the default URI.

CVE-2019-18930
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.

CVE-2019-12942
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable.

CVE-2019-2399
Communications Diameter Signaling Router (DSR) Web Networking Database Cloud
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) component of Oracle Communications Applications (subcomponent: Security). The supported version that is affected is prior to 8.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data and unauthorized ability to cause a partial denial of service (part

CVE-2019-9745
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used to import data from CRM software using plugins (.dll files). The plugin to import data from the EXQUISE software (DatasourceExquiseExporter.dll) can be persuaded to start arbitrary programs (including batch files) that are executed using the same privileges as Recognition Update Client Service (NT AUTHORITY\SYSTEM)

CVE-2015-2263
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2015 1 PoC

Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.

CVE-2019-9158
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.

CVE-2019-15623
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-359 1 PoC

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

CVE-2007-2958
Software Genérico Cloud
N/A
UNKNOWN
EPSS
4.5%
2007 2 PoCs

Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

CVE-2007-2054
Software Genérico Cloud
N/A
UNKNOWN
EPSS
2.6%
2007 1 PoC

Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp. NOTE: the aimage.cpp vector (e) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.

CVE-2007-1728
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

The Remote Play feature in Sony Playstation 3 (PS3) 1.60 and Playstation Portable (PSP) 3.10 OE-A allows remote attackers to cause a denial of service via a flood of UDP packets.

CVE-2014-3220
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
31.9%
2014 1 PoC

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.

CVE-2014-1449
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.

CVE-2015-6023
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
21.6%
2015 4 PoCs

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE: this issue can be combined with CVE-2015-6024 to execute arbitrary commands.

CVE-2019-15616
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-93 1 PoC

Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

CVE-2019-10266
Software Genérico Cloud
N/A
UNKNOWN
EPSS
18.6%
2019 1 PoC

An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.

CVE-2019-18307
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-125 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, and CVE-2019-18306. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnera