3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-19093
eSOMS General
6.5
MEDIUM
EPSS
0.2%
2019 CWE-521 1 PoC

eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.

CVE-2019-10800
codecov General
6.5
MEDIUM
EPSS
0.3%
2019 1 PoC

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

CVE-2019-13988
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2019 1 PoC

Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).

CVE-2019-5014
Winco Firefly General
6.5
MEDIUM
EPSS
0.1%
2019 CWE-284 1 PoC

An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.

CVE-2019-5786
🔥 KEV Chrome General
6.5
MEDIUM
EPSS
89.4%
2019 1 PoC

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2019-4252
Rational Collaborative Lifecycle Management General
6.5
MEDIUM
EPSS
0.6%
2019 1 PoC

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 159883.

CVE-2019-3474
Filr General
6.5
MEDIUM
EPSS
3.3%
2019 CWE-22 1 PoC

A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

CVE-2019-16671
Software Genérico General
6.5
MEDIUM
EPSS
1.0%
2019 2 PoCs

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special packet because of Uncontrolled Resource Consumption.

CVE-2019-11476
Whoopsie General
6.5
MEDIUM
EPSS
0.1%
2019 CWE-190 2 PoCs

An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the whoopsie process.

CVE-2019-3740
RSA BSAFE Crypto-J General
6.5
MEDIUM
EPSS
1.2%
2019 CWE-310 6 PoCs

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.

CVE-2019-9493
MyCar Controls General
6.5
MEDIUM
EPSS
9.2%
2019 CWE-798 1 PoC

The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit. This may allow the attacker to learn the location of a target, or gain unauthorized physical access to a vehicle. This issue affects AutoMobility MyCar versions prior to 3.4.24 on iOS and versions prior to 4.1.2 on Android. This issue has additionally been fixed in Carlink, Link, Visions MyCar, and MyCar Kia.

CVE-2019-3599
McAfee Agent (MA) General
6.5
MEDIUM
EPSS
0.3%
2019 1 PoC

Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information via remote logging when it is enabled.

CVE-2019-3738
RSA BSAFE Crypto-J General
6.5
MEDIUM
EPSS
1.0%
2019 CWE-325 7 PoCs

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.

CVE-2019-6693
🔥 KEV FortiGate General
6.5
MEDIUM
EPSS
72.2%
2019 3 PoCs

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

CVE-2019-3739
RSA BSAFE Crypto-J General
6.5
MEDIUM
EPSS
1.2%
2019 CWE-310 6 PoCs

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.

CVE-2019-5020
Yara Object General
6.5
MEDIUM
EPSS
0.3%
2019 CWE-617 1 PoC

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.

CVE-2019-10131
ImageMagick General
6.5
MEDIUM
EPSS
0.1%
2019 CWE-193 1 PoC

An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

CVE-2019-20659
Software Genérico General
6.4
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

CVE-2019-4178
Cognos Analytics General
6.4
MEDIUM
EPSS
0.5%
2019 1 PoC

IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to write or view arbitrary files on the system. IBM X-Force ID: 158919.

CVE-2019-3759
RSA Identity Governance and Lifecycle General
6.4
MEDIUM
EPSS
1.2%
2019 CWE-94 2 PoCs

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.