3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-15588
Nexus Repository Manager General
N/A
UNKNOWN
EPSS
7.3%
2019 CWE-77 4 PoCs

There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.

CVE-2019-10018
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.

CVE-2019-7282
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

CVE-2019-14261
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2019 4 PoCs

An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF messages sent between wireless peripheral components, e.g., wireless detectors or remote controls, and the ABUS Secvest alarm central. An attacker is able to perform a "reactive jamming" attack. The reactive jamming simply detects the start of a RF message sent by a component of the ABUS Secvest wireless alarm system, for instance a wireless motion detector (FUBW50000) or a remote control (FUBE50014 or FUBE50015), a

CVE-2019-20387
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

CVE-2019-9278
Android General
N/A
UNKNOWN
EPSS
3.7%
2019 1 PoC

In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774

CVE-2019-12222
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.

CVE-2019-18389
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.

CVE-2019-19455
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza Streaming Engine 4.8.5.

CVE-2019-19743
Software Genérico General
N/A
UNKNOWN
EPSS
13.9%
2019 2 PoCs

On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

CVE-2019-19937
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."