3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-20481
Software Genérico General
4.6
MEDIUM
EPSS
0.3%
2019 1 PoC

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

CVE-2019-25349
scadaApp for iOS General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices.

CVE-2019-3653
McAfee Endpoint Security (ENS) General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-284 1 PoC

Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.

CVE-2019-25326
ipPulse General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

ipPulse 1.92 contains a denial of service vulnerability that allows local attackers to crash the application by providing an oversized input in the Enter Key field. Attackers can generate a 256-byte buffer of repeated 'A' characters to trigger an application crash when pasting the malicious content.

CVE-2019-4723
Cognos Analytics General
4.6
MEDIUM
EPSS
0.5%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.

CVE-2019-25350
XMedia Recode General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-770 1 PoC

XMedia Recode 3.4.8.6 contains a denial of service vulnerability that allows attackers to crash the application by loading a specially crafted .m3u playlist file. Attackers can create a malicious .m3u file with an oversized buffer to trigger an application crash when the file is opened.

CVE-2019-20469
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2019 1 PoC

An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by connecting via a USB cable.

CVE-2019-4724
Cognos Analytics General
4.6
MEDIUM
EPSS
0.5%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.

CVE-2019-25354
iSmartViewPro General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the camera ID input field. Attackers can paste a 257-character buffer into the camera DID and password fields to trigger an application crash on iOS devices.

CVE-2019-3842
systemd General
4.5
MEDIUM
EPSS
0.1%
2019 CWE-285 2 PoCs

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".

CVE-2019-6192
Power Management driver General
4.4
MEDIUM
EPSS
2.1%
2019 1 PoC

A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.

CVE-2019-20739
Software Genérico General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

NETGEAR R8500 devices before v1.0.2.128 are affected by a buffer overflow by an unauthenticated attacker.

CVE-2019-4722
Cognos Analytics General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.

CVE-2019-25064
Core Portal General
4.3
MEDIUM
EPSS
0.1%
2019 CWE-352 1 PoC

A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. Upgrading to version 27.0.8 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2019-4334
Cognos Analytics General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in future attacks against the system. IBM X-Force ID: 161271.

CVE-2019-4556
Qradar Advisor General
4.3
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 166205.

CVE-2019-20654
Software Genérico General
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

CVE-2019-18997
PB610 Panel Builder 600 General
4.3
MEDIUM
EPSS
0.4%
2019 CWE-424 1 PoC

The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.

CVE-2019-4047
Jazz Reporting Service General
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.

CVE-2019-4084
Rational Collaborative Lifecycle Management General
4.3
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) could allow an authenticated user to obtain sensitive information from CLM Applications that could be used in further attacks against the system. IBM X-Force ID: 157384.