9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2018-4033
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access could use this vulnerability to modify the file system as root.

CVE-2018-4034
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with local access could use this vulnerability to modify the file system as root.

CVE-2018-4041
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVE-2018-25146
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Service Control DoS General
7.1
HIGH
EPSS
0.1%
2018 CWE-863 2 PoCs

Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring device restart.

CVE-2018-19879
Software Genérico General
7.1
HIGH
EPSS
0.5%
2018 1 PoC

An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.

CVE-2018-2019
Security Identity Manager General
7.1
HIGH
EPSS
0.5%
2018 1 PoC

IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 155265.

CVE-2018-4044
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVE-2018-4047
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVE-2018-5378
bgpd General
7.1
HIGH
EPSS
9.3%
2018 CWE-119 1 PoC

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.

CVE-2018-4043
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user with local access can use this vulnerability to modify the file system as root. An attacker would need local access to the machine for a successful exploit.

CVE-2018-25311
VideoFlow Digital Video Protection General
7.1
HIGH
EPSS
0.4%
2018 CWE-22 2 PoCs

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, download.pl, downloadmib.pl, or downloadFile.pl with directory traversal payloads to read sensitive system files like /etc/passwd.

CVE-2018-4045
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVE-2018-4017
Anker General
7.1
HIGH
EPSS
0.1%
2018 1 PoC

An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability.

CVE-2018-4032
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the way the CleanMyMac X software improperly validates inputs. An attacker with local access could use this vulnerability to modify the file system as root. An attacker would need local access to the machine for a successful exploit.

CVE-2018-21097
Software Genérico General
7.1
HIGH
EPSS
0.4%
2018 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WAC120 before 2.1.7, WN604 before 3.3.10, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7, and WND930 before 2.1.5.

CVE-2018-4036
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access could use this vulnerability to modify the running kernel extensions on the system.

CVE-2018-4055
Pixar Renderman General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman, version 22.2.0. A user with local access can use this vulnerability to read any root file from the file system. An attacker would need local access to the machine to successfully exploit this flaw.

CVE-2018-25312
ClearSea General
7.1
HIGH
EPSS
1.1%
2018 CWE-22 1 PoC

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.

CVE-2018-4042
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVE-2018-4046
Clean My Mac General
7.1
HIGH
EPSS
0.0%
2018 1 PoC

An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. A user with local access can use this vulnerability to terminate a privileged helper application. An attacker would need local access to the machine for a successful exploit.