9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-20470
Software Genérico General
7.5
HIGH
EPSS
1.2%
2019 1 PoC

An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated by sending a specific SMS and using the default password, e.g., pw,<password>,call,<mobile_number> triggers an outbound call from the watch. The password is sometimes available because of CVE-2019-20471.

CVE-2019-1367
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
90.7%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

CVE-2019-19956
Software Genérico General
7.5
HIGH
EPSS
0.2%
2019 1 PoC

xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

CVE-2019-1429
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
83.0%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

CVE-2019-10174
infinispan General
7.5
HIGH
EPSS
0.9%
2019 CWE-470 1 PoC

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

CVE-2019-5037
Nest Labs General
7.5
HIGH
EPSS
0.1%
2019 CWE-190 1 PoC

An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.

CVE-2019-3628
McAfee Enterprise Security Manager (ESM) General
7.5
HIGH
EPSS
0.8%
2019 1 PoC

Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control.

CVE-2019-5137
Moxa General
7.5
HIGH
EPSS
0.5%
2019 CWE-321 1 PoC

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

CVE-2019-10936
Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller General
7.5
HIGH
EPSS
2.0%
2019 CWE-400 1 PoC

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

CVE-2019-25073
github.com/goadesign/goa General
7.5
HIGH
EPSS
0.6%
2019 1 PoC

Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.

CVE-2019-9564
Cam Pan v2 General
7.5
HIGH
EPSS
0.4%
2019 1 PoC

A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

CVE-2019-5091
LEADTOOLS libltdic.so General
7.5
HIGH
EPSS
0.4%
2019 CWE-835 1 PoC

An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an infinite loop, resulting in a denial of service. An attacker can send a packet to trigger this vulnerability.

CVE-2019-5188
E2fsprogs General
7.5
HIGH
EPSS
0.1%
2019 CWE-787 1 PoC

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVE-2019-9099
Software Genérico General
7.5
HIGH
EPSS
9.1%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).

CVE-2019-15961
ClamAV General
7.5
HIGH
EPSS
2.2%
2019 CWE-20 2 PoCs

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denia

CVE-2019-20464
Software Genérico General
7.5
HIGH
EPSS
0.4%
2019 1 PoC

An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable streaming. Although the service used by the mobile application requires a password, the other streaming services do not. By initiating communication on the RTSP port, an attacker can obtain access to the video feed without authenticating.

CVE-2019-5047
NitroPDF General
7.5
HIGH
EPSS
0.0%
2019 CWE-416 1 PoC

An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker can craft a malicious PDF to trigger this vulnerability.

CVE-2019-11477
Linux kernel General
7.5
HIGH
EPSS
69.9%
2019 CWE-190 7 PoCs

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.

CVE-2021-40142
Software Genérico General
7.5
HIGH
EPSS
0.5%
2021 2 PoCs

In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.

CVE-2021-25485
Samsung Mobile Devices General
7.5
HIGH
EPSS
0.1%
2021 CWE-20 1 PoC

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.