3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-3759
RSA Identity Governance and Lifecycle General
6.4
MEDIUM
EPSS
1.2%
2019 CWE-94 2 PoCs

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

CVE-2019-20745
Software Genérico General
6.4
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2 and WAC510 before 5.0.10.2.

CVE-2019-6170
ThinkPad General
6.4
MEDIUM
EPSS
0.1%
2019 1 PoC

A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.

CVE-2019-10143
freeradius General
6.4
MEDIUM
EPSS
0.1%
2019 CWE-266 2 PoCs

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."

CVE-2019-6172
ThinkPad General
6.4
MEDIUM
EPSS
0.1%
2019 1 PoC

A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.

CVE-2019-11850
Software Genérico General
6.3
MEDIUM
EPSS
0.0%
2019 1 PoC

A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution

CVE-2019-10181
icedtea-web General
6.3
MEDIUM
EPSS
0.4%
2019 CWE-345 2 PoCs

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVE-2019-20740
Software Genérico General
6.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R7300 before 1.0.0.70, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

CVE-2019-20703
Software Genérico General
6.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

CVE-2019-3900
Kernel General
6.3
MEDIUM
EPSS
0.2%
2019 CWE-835 5 PoCs

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.

CVE-2019-25071
iOS General
6.3
MEDIUM
EPSS
0.7%
2019 CWE-269 1 PoC

A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit details have been disclosed to the public. The existence and implications of this vulnerability are doubted by Apple even though multiple public videos demonstrating the attack exist. Upgrading to version 13.0 migt be able to address this issue. It is recommended to upgrade affected devices. NOTE: Apple claims, that after exa

CVE-2019-25065
OpenNetAdmin General
6.3
MEDIUM
EPSS
73.7%
2019 CWE-78 3 PoCs

A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2019-11484
whoopsie General
6.3
MEDIUM
EPSS
0.1%
2019 CWE-190 1 PoC

Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.

CVE-2019-3849
moodle General
6.3
MEDIUM
EPSS
0.4%
2019 CWE-285 1 PoC

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVE-2019-20705
Software Genérico General
6.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

CVE-2019-20472
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2019 1 PoC

An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device.

CVE-2019-5139
Moxa General
6.2
MEDIUM
EPSS
0.1%
2019 CWE-798 1 PoC

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

CVE-2019-18899
Leap 15.1 General
6.2
MEDIUM
EPSS
0.1%
2019 CWE-269 1 PoC

The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.

CVE-2019-3016
linux_kernel General
6.2
MEDIUM
EPSS
0.1%
2019 CWE-362 1 PoC

In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.

CVE-2019-9095
Software Genérico General
6.2
MEDIUM
EPSS
0.2%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and gain administrative access.