3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-25686
Core FTP General
8.7
HIGH
EPSS
0.2%
2019 CWE-306 1 PoC

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

CVE-2019-25605
EquityPandit General
8.7
HIGH
EPSS
0.0%
2019 CWE-612 1 PoC

EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.

CVE-2019-25236
Hybrid DVR WH-H4 General
8.7
HIGH
EPSS
0.1%
2019 CWE-306 2 PoCs

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.

CVE-2019-25358
FileOptimizer General
8.7
HIGH
EPSS
0.0%
2019 CWE-1282 1 PoC

FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options.

CVE-2019-25401
MP-4200 General
8.7
HIGH
EPSS
0.2%
2019 CWE-400 1 PoC

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page. Remote attackers can send crafted POST requests with malformed 'admin' and 'person' parameters to crash the printer's web service, causing a denial of service condition.

CVE-2019-25465
HiIpcam General
8.7
HIGH
EPSS
0.4%
2019 CWE-260 1 PoC

Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network configuration parameters including usernames, passwords, and DNS settings.

CVE-2019-25613
Easy Chat General
8.7
HIGH
EPSS
0.4%
2019 CWE-940 1 PoC

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.

CVE-2019-25240
DVR General
8.7
HIGH
EPSS
0.1%
2019 CWE-306 2 PoCs

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

CVE-2019-25470
eWON General
8.7
HIGH
EPSS
0.1%
2019 CWE-798 1 PoC

eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint. Attackers can send POST requests to /wrcgi.bin/wsdReadForm with base64-encoded partial credentials and a crafted wsdList parameter to extract encrypted passwords for all users, which can be decrypted using a hardcoded XOR key.

CVE-2019-25249
dLAN 550 duo+ Starter Kit General
8.7
HIGH
EPSS
0.2%
2019 CWE-266 2 PoCs

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.

CVE-2019-25248
N100 H.264 VGA IP Camera General
8.7
HIGH
EPSS
0.2%
2019 CWE-306 2 PoCs

Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve the camera's RTSP stream by exploiting the lack of authentication in the video access mechanism.

CVE-2019-25654
Core FTP/SFTP Server General
8.7
HIGH
EPSS
0.1%
2019 CWE-787 1 PoC

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.

CVE-2019-25229
Xperience General
8.7
HIGH
EPSS
0.1%
2019 CWE-434 1 PoC

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

CVE-2019-25257
LogicalDOC Enterprise General
8.7
HIGH
EPSS
0.1%
2019 CWE-426 2 PoCs

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

CVE-2019-25560
Lyric Video Creator General
8.7
HIGH
EPSS
0.1%
2019 CWE-226 1 PoC

Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.

CVE-2019-25552
CEWE PHOTO SHOW General
8.7
HIGH
EPSS
0.1%
2019 CWE-836 1 PoC

CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Attackers can paste a large string of repeated characters into the password input during the upload process to trigger an application crash.

CVE-2019-25604
DVDXPlayer General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

DVDXPlayer Pro 5.5 contains a local buffer overflow vulnerability with structured exception handling that allows local attackers to execute arbitrary code by crafting malicious playlist files. Attackers can create a specially crafted .plf file containing shellcode and NOP sleds that overflows a buffer and hijacks the SEH chain to execute arbitrary code with application privileges.

CVE-2019-25705
Echo Mirage General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized string in the Rules action field. Attackers can create a malicious text file with a crafted payload exceeding buffer boundaries and paste it into the action field through the Rules dialog to trigger the overflow and overwrite the return address.

CVE-2019-25627
FlexHEX General
8.6
HIGH
EPSS
0.0%
2019 CWE-434 1 PoC

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

CVE-2019-25467
docPrint Pro General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 2 PoCs

Verypdf docPrint Pro 8.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized alphanumeric encoded payload in the User Password or Master Password fields. Attackers can craft a malicious payload with encoded shellcode and SEH chain manipulation to bypass protections and execute a MessageBox proof-of-concept when the password fields are processed during PDF encryption.