1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2020-13467
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.

CVE-2019-5523
VMware vCloud Director for Service Providers (vCD) Cloud
N/A
UNKNOWN
EPSS
2.5%
2019 1 PoC

VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Portals by impersonating a currently logged in session.

CVE-2020-9030
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.

CVE-2015-1787
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
25.8%
2015 8 PoCs

The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero.

CVE-2019-5454
com.nextcloud.client Database Cloud
N/A
UNKNOWN
EPSS
0.5%
2019 CWE-89 1 PoC

SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.

CVE-2020-8278
Nextcloud Social Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-284 1 PoC

Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.

CVE-2020-35608
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.

CVE-2020-15328
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.

CVE-2019-18293
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
2.0%
2019 CWE-122 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVE-2020-8122
Nextcloud server Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-284 1 PoC

A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

CVE-2020-8162
https://github.com/rails/rails Web Cloud
N/A
UNKNOWN
EPSS
1.5%
2020 CWE-602 1 PoC

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVE-2019-5453
com.nextcloud.client Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-288 1 PoC

Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.

CVE-2020-8152
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-522 3 PoCs

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.

CVE-2019-18298
SPPA-T3000 MS3000 Migration Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-190 1 PoC

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnera

CVE-2020-15864
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.

CVE-2007-0779
Software Genérico Cloud
N/A
UNKNOWN
EPSS
4.1%
2007 3 PoCs

GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.

CVE-2007-5909
Software Genérico Cloud
N/A
UNKNOWN
EPSS
25.9%
2007 3 PoCs

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.

CVE-2014-8373
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.4%
2014 2 PoCs

The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain privileges via vectors involving the "Connect (by) Using VMRC" function.

CVE-2014-5636
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Cloud Browser (aka com.granitamalta.cloudbrowser) application 2.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-5329
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.