3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-5371
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-10486
Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8939, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM71

CVE-2019-20044
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 3 PoCs

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

CVE-2019-15414
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ZenFone AR Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-

CVE-2019-16733
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2019 1 PoC

processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.

CVE-2019-15396
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ZenFone 3 Android device with a build fingerprint of asus/WW_Phone/ASUS_Z012D:7.0/NRD90M/14.2020.1708.56-20170719:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed

CVE-2019-16165
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.

CVE-2019-18184
Software Genérico General
N/A
UNKNOWN
EPSS
21.4%
2019 1 PoC

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

CVE-2019-25036
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

CVE-2019-12506
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 4 PoCs

Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.

CVE-2019-7812
Adobe Acrobat and Reader General
N/A
UNKNOWN
EPSS
2.9%
2019 1 PoC

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVE-2019-18951
Software Genérico General
N/A
UNKNOWN
EPSS
71.5%
2019 1 PoC

SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.

CVE-2019-14371
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

CVE-2019-20622
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband stack overflow. The Samsung ID is SVE-2018-13188 (February 2019).

CVE-2019-19614
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1.

CVE-2019-17356
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 2 PoCs

The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during login, as demonstrated by sniffing of a public Wi-Fi network.

CVE-2019-17051
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.

CVE-2019-16072
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.3%
2019 1 PoC

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

CVE-2019-19610
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.

CVE-2019-8956
Linux Kernel General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.