3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-25332
FTP Commander Pro General
8.4
HIGH
EPSS
0.1%
2019 CWE-121 2 PoCs

FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.

CVE-2019-25327
Prime95 General
8.4
HIGH
EPSS
0.3%
2019 CWE-122 1 PoC

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.

CVE-2019-11540
Software Genérico General
8.3
HIGH
EPSS
6.3%
2019 1 PoC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

CVE-2019-10761
vm2 General
8.3
HIGH
EPSS
0.8%
2019 2 PoCs

This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.

CVE-2019-20760
Software Genérico General
8.3
HIGH
EPSS
0.2%
2019 1 PoC

NETGEAR R9000 devices before 1.0.4.26 are affected by authentication bypass.

CVE-2019-3629
McAfee Enterprise Security Manager (ESM) General
8.3
HIGH
EPSS
1.2%
2019 1 PoC

Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters.

CVE-2019-17390
Software Genérico General
8.2
HIGH
EPSS
0.1%
2019 1 PoC

An issue was discovered in the Outlook add-in in Pronestor Planner before 8.1.77. There is local privilege escalation in the Health Monitor service because PronestorHealthMonitor.exe access control is mishandled, aka PNB-2359.

CVE-2019-10182
icedtea-web General
8.2
HIGH
EPSS
1.1%
2019 CWE-22 2 PoCs

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

CVE-2019-16536
DB General
8.2
HIGH
EPSS
0.3%
2019 CWE-120 1 PoC

Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

CVE-2019-10185
icedtea-web General
8.2
HIGH
EPSS
1.9%
2019 CWE-22 2 PoCs

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVE-2019-5040
Nest Labs General
8.2
HIGH
EPSS
0.1%
2019 CWE-190 1 PoC

An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.

CVE-2019-20734
Software Genérico General
8.2
HIGH
EPSS
0.5%
2019 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.40, D8500 before 1.0.3.39, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.22, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150v1 before 1.0.0.42, EX6200 before 1.0.3.88, EX7000 before 1.0.0.66, R6300v2 before 1.0.4.18, R6400 before 1.0.1.24, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6700v3 before 1.0.2.32, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R6900P before 1.0.0.56, R7000P before 1.0.0.56, R7100LG before 1.0.

CVE-2019-11855
Software Genérico General
8.1
HIGH
EPSS
0.0%
2019 1 PoC

An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

CVE-2019-5144
Kakadu Software General
8.1
HIGH
EPSS
3.2%
2019 CWE-191 1 PoC

An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file to the victim to trigger this vulnerability.

CVE-2019-18568
Antivirus Free Antivirus General
8.1
HIGH
EPSS
0.1%
2019 CWE-680 1 PoC

Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.

CVE-2019-5093
LEADTOOLS libltdic.so General
8.1
HIGH
EPSS
0.3%
2019 CWE-190 1 PoC

An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a packet to trigger this vulnerability.

CVE-2019-20651
Software Genérico General
8.1
HIGH
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16.

CVE-2019-3638
Web Gateway(MWG) General
8.1
HIGH
EPSS
1.0%
2019 1 PoC

Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.

CVE-2019-3631
McAfee Enterprise Security Manager (ESM) General
8.0
HIGH
EPSS
2.8%
2019 1 PoC

Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.

CVE-2019-5165
Moxa General
8.0
HIGH
EPSS
0.2%
2019 CWE-288 1 PoC

An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.