3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-9600
Software Genérico General
N/A
UNKNOWN
EPSS
17.8%
2019 2 PoCs

The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain packets.

CVE-2019-13118
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVE-2019-10494
Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660,

CVE-2019-5338
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-10023
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.

CVE-2019-20848
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.

CVE-2019-14088
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Possible use after free issue while CRM is accessing the link pointer from device private data due to lack of resource protection in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, MDM9206, MDM9207C, MDM9607, QCS605, SDM429W, SDX24, SM8150, SXR1130

CVE-2019-15642
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2019 1 PoC

rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."

CVE-2019-13418
Search Guard General
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-311 1 PoC

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

CVE-2019-7613
Logstash General
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-778 1 PoC

Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.

CVE-2019-5170
WAGO PFC200 General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e87c the extracted hostname value from the xml file is used as an argument to /etc/config-tools/change_hostname hostname=<contents of hostname node> using sprintf(). This command is later executed via a call to system().

CVE-2019-5596
FreeBSD General
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.

CVE-2019-19815
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.

CVE-2019-19225
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2019 1 PoC

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers without being authenticated on the admin interface by submitting a crafted Forms/dns_1 POST request.

CVE-2019-16112
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.

CVE-2019-5365
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-20864
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermost account to a different person's GitHub account.

CVE-2019-1010252
ONOS General
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management and connectivity.

CVE-2019-15461
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

CVE-2019-10871
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.