3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-25230
Xperience General
5.3
MEDIUM
EPSS
0.1%
2019 CWE-497 1 PoC

An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.

CVE-2019-3874
kernel General
5.3
MEDIUM
EPSS
0.2%
2019 CWE-400 3 PoCs

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

CVE-2019-3650
Advanced Threat Defense (ATD) General
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET request extracting insecurely information stored in the database.

CVE-2019-5043
Nest Labs General
5.3
MEDIUM
EPSS
0.2%
2019 CWE-400 1 PoC

An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multiple times to trigger this vulnerability.

CVE-2019-15165
Software Genérico General
5.3
MEDIUM
EPSS
1.0%
2019 1 PoC

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

CVE-2019-20694
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects GS728TP before 6.0.0.48, GS728TPPv2 before 6.0.0.48, GS728TPv2 before 6.0.0.48, GS752TPP before 6.0.0.48, and GS752TPv2 before 6.0.0.48.

CVE-2019-25062
IP CCTV Camera General
5.3
MEDIUM
EPSS
0.1%
2019 CWE-121 2 PoCs

A vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processing of the component Device Viewer. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVE-2019-3643
McAfee Web Gateway (MWG) General
5.3
MEDIUM
EPSS
0.5%
2019 1 PoC

McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.

CVE-2019-3649
Advanced Threat Defense (ATD) General
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.

CVE-2019-25323
Heatmiser Netmonitor General
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate the web interface's displayed content.

CVE-2019-25282
V-SOL GPON/EPON OLT Platform General
5.1
MEDIUM
EPSS
0.1%
2019 CWE-601 1 PoC

V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipulate the 'parent' GET parameter. Attackers can craft malicious links that redirect logged-in users to arbitrary websites by exploiting improper input validation in the redirect mechanism.

CVE-2019-25436
DeviceViewer General
5.1
MEDIUM
EPSS
0.0%
2019 CWE-303 1 PoC

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password.

CVE-2019-5068
Mesa 3D X11 Graphics library General
5.1
MEDIUM
EPSS
0.1%
2019 CWE-277 1 PoC

An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.

CVE-2019-3652
McAfee Endpoint Security (ENS) General
5.0
MEDIUM
EPSS
0.1%
2019 CWE-94 1 PoC

Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.

CVE-2019-10212
undertow General
4.8
MEDIUM
EPSS
0.4%
2019 CWE-532 1 PoC

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

CVE-2019-10207
kernel General
4.7
MEDIUM
EPSS
0.7%
2019 CWE-476 1 PoC

A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.

CVE-2019-3882
kernel General
4.7
MEDIUM
EPSS
0.0%
2019 CWE-770 2 PoCs

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.

CVE-2019-8995
TIBCO ActiveMatrix BPM General
4.7
MEDIUM
EPSS
0.2%
2019 1 PoC

The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a vulnerability wherein a malicious URL could trick a user into visiting a website of the attacker's choice. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up to and including 4.2.0, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM

CVE-2019-20648
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2019 1 PoC

NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.

CVE-2019-20481
Software Genérico General
4.6
MEDIUM
EPSS
0.3%
2019 1 PoC

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.