3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-18367
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

CVE-2019-20478
Software Genérico General
N/A
UNKNOWN
EPSS
7.3%
2019 1 PoC

In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.

CVE-2019-9648
Software Genérico General
N/A
UNKNOWN
EPSS
19.7%
2019 3 PoCs

An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.

CVE-2019-19815
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.

CVE-2019-17132
Software Genérico General
N/A
UNKNOWN
EPSS
25.2%
2019 2 PoCs

vBulletin through 5.5.4 mishandles custom avatars.

CVE-2019-15809
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because the Atmel Toolbox 00.03.11.05 contains two versions of ECDSA signature functions, described as fast and secure, but the affected cards chose to use the fast version, which leaks the bit length of the random nonce via timing. This affects Athena IDProtect 010b.0352.000

CVE-2019-19225
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2019 1 PoC

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers without being authenticated on the admin interface by submitting a crafted Forms/dns_1 POST request.

CVE-2019-16112
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.

CVE-2019-5365
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-20864
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermost account to a different person's GitHub account.

CVE-2019-1010252
ONOS General
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management and connectivity.

CVE-2019-15461
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

CVE-2019-10871
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

CVE-2019-19383
Software Genérico General
N/A
UNKNOWN
EPSS
25.1%
2019 1 PoC

freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).

CVE-2019-3925
Crestron AirMedia General
N/A
UNKNOWN
EPSS
16.2%
2019 CWE-79 1 PoC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVE-2019-11351
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.

CVE-2019-20621
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).

CVE-2019-20846
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.

CVE-2019-17000
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.

CVE-2019-17596
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2019 1 PoC

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.