1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2019-15310
Software Genérico Cloud
N/A
UNKNOWN
EPSS
11.9%
2019 1 PoC

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

CVE-2015-5713
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2015 1 PoC

Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote attackers to obtain sensitive log information by visiting an unspecified URL.

CVE-2019-13498
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

CVE-2019-15620
Nextcloud Talk Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-287 1 PoC

Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.

CVE-2014-9690
WS318 V100R001C01B022 and earlier versions Cloud
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerability of the WPS protocol because the random number generator (RNG) used in the supplier's solution is not random enough. As a result, brute force cracking the PIN code is easier. After an attacker cracks the PIN, the attacker can access the Internet via the cracked device.

CVE-2015-2608
Software Genérico Networking Database Cloud
N/A
UNKNOWN
EPSS
2.5%
2015 1 PoC

Unspecified vulnerability in (1) the Oracle Communications Diameter Signaling Router (DSR) component in Oracle Communications Applications 4.1.6 and earlier, 5.1.0 and earlier, 6.0.2 and earlier, and 7.1.0 and earlier; (2) the Oracle Communications Performance Intelligence Center Software component in Oracle Communications Applications 9.0.3 and earlier and 10.1.5 and earlier; (3) the Oracle Communications Policy Management component in Oracle Communications Applications 9.9.0 and earlier, 10.5.0 and earlier, 11.5.0 and earlier, and 12.1.0 and earlier; and (4) the Oracle Communications Tekelec

CVE-2019-15617
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-287 1 PoC

A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

CVE-2019-15621
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.

CVE-2015-4554
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.5%
2015 1 PoC

Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Deployment Kit before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Desktop before 6.5.2 and 7.0.x before 7.0.1; Spotfire Desktop Language Packs 7.0.x before 7.0.1; Spotfire Professional before 5

CVE-2023-46157
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.

CVE-2019-18289
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
2.0%
2019 CWE-122 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18293, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE-2019-15452
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Samsung J3 Android device with a build fingerprint of samsung/j3y17ltedx/j3y17lte:8.0.0/R16NW/J330GDXS3BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=6010000, versionName=6.1.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

CVE-2019-18296
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
2.0%
2019 CWE-122 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18293, and CVE-2019-18295. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE-2014-1665
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

CVE-2014-5659
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The ASTRO File Manager with Cloud (aka com.metago.astro) application ASTRO-4.4.592 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-8024
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
1.5%
2015 1 PoC

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass authentication by logging in with the username "NGCP|NGCP|NGCP;" and any password.

CVE-2019-5476
lookup.nextcloud.com Web Database Cloud
N/A
UNKNOWN
EPSS
0.6%
2019 CWE-89 2 PoCs

An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.

CVE-2019-10777
aws-lambda Cloud
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".

CVE-2019-15614
Nextcloud iOS App Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-79 1 PoC

Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.

CVE-2015-1516
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.