2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-13541
Win-911 General
9.3
CRITICAL
EPSS
0.1%
2020 CWE-276 2 PoCs

An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Depending on the vector chosen, an attacker can overwrite the service executable and execute arbitrary code with System privileges or replace other files within the installation folder that could lead to local privilege escalation.

CVE-2020-13534
Dream Report General
9.3
CRITICAL
EPSS
0.2%
2020 CWE-276 1 PoC

A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges which can lead to privilege escalation when used. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2016-20049
JAD Java Decompiler General
9.3
CRITICAL
EPSS
0.1%
2016 CWE-787 1 PoC

JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute shellcode in the application context.

CVE-2016-20030
ZKTeco ZKBioSecurity General
9.3
CRITICAL
EPSS
0.0%
2016 CWE-551 1 PoC

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.

CVE-2016-20024
ZKTeco ZKTime.Net General
9.3
CRITICAL
EPSS
0.0%
2016 CWE-538 2 PoCs

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.

CVE-2018-3971
Sophos General
9.3
CRITICAL
EPSS
0.0%
2018 1 PoC

An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.

CVE-2018-25223
Crashmail General
9.3
CRITICAL
EPSS
0.4%
2018 CWE-787 1 PoC

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

CVE-2018-25272
ELBA5 General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-326 1 PoC

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and execute commands via the xp_cmdshell stored procedure or add backdoor users to the BEDIENER table.

CVE-2018-25221
EChat Server General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-787 1 PoC

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.

CVE-2018-25159
AVCON6 systems management platform General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-1334 1 PoC

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.

CVE-2018-3974
GOG Galaxy General
9.3
CRITICAL
EPSS
0.0%
2018 1 PoC

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overwrite an executable that is launched as a system service on boot by default to exploit this vulnerability and execute arbitrary code with system privileges.

CVE-2018-25134
netBooter NP-02x/NP-08x General
9.3
CRITICAL
EPSS
0.4%
2018 CWE-306 2 PoCs

Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain unauthorized control over power supply management.

CVE-2018-25135
Anviz AIM CrossChex Standard General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-149 2 PoCs

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

CVE-2018-25220
BOCHS General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-787 1 PoC

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite the instruction pointer and execute shell commands with application privileges.

CVE-2018-25316
W General
9.3
CRITICAL
EPSS
0.2%
2018 CWE-290 1 PoC

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS servers and redirect user traffic to malicious sites.

CVE-2018-25147
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Default Credentials General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-1392 2 PoCs

Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

CVE-2018-25254
NICO-FTP General
9.3
CRITICAL
EPSS
0.3%
2018 CWE-787 1 PoC

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

CVE-2018-25120
DNS-343 ShareCenter General
9.3
CRITICAL
EPSS
1.2%
2018 CWE-78 1 PoC

D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters directly in a call to a system email utility without proper input validation. An unauthenticated remote attacker can supply crafted form data that injects shell commands, resulting in execution as root on the device. NOTE: The DNS-343 product line has been declared end-of-life.

CVE-2018-25318
FH303/A300 General
9.3
CRITICAL
EPSS
0.2%
2018 CWE-290 1 PoC

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites.

CVE-2018-3990
Software Genérico General
9.3
CRITICAL
EPSS
0.2%
2018 1 PoC

An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.