3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-20588
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SEM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14891 (August 2019).

CVE-2019-19047
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, aka CID-c7ed6d0183d5.

CVE-2019-10789
curling.js General
N/A
UNKNOWN
EPSS
8.3%
2019 1 PoC

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

CVE-2019-14245
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2019 3 PoCs

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.

CVE-2019-18665
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 0 PoCs

The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.

CVE-2019-10536
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is not set to NULL on first call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6174A, QCA6574AU, Q

CVE-2019-8339
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine.

CVE-2019-20883
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.

CVE-2019-7672
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.

CVE-2019-20564
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered on Samsung mobile devices with any (before October 2019 for S9 or Note9) software. Attackers can manipulate the IMEI. The Samsung ID is SVE-2019-15435 (October 2019).

CVE-2019-25044
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 3 PoCs

The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.

CVE-2019-11873
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2019 1 PoC

wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length, client hello length, total extensions length, PSK extension length, total identity length, and identity length contain their maximum value which is 2^16. The identity data field of the PSK extension of the packet contains the attack data, to be stored in the undefined memory (RAM) of the server. The size of the data is ab

CVE-2019-8442
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2019 0 PoCs

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.

CVE-2019-13131
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2019 1 PoC

Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

CVE-2019-3971
Comodo Antivirus General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to a local Denial of Service affecting CmdVirth.exe via its LPC port "cmdvrtLPCServerPort". A low privileged local process can connect to this port and send an LPC_DATAGRAM, which triggers an Access Violation due to hardcoded NULLs used for Source parameter in a memcpy operation that is called for this handler. This results in CmdVirth.exe and its child svchost.exe instances to terminate.

CVE-2019-15743
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys contains a pre-installed app with a package name of com.sonymobile.android.maintenancetool.testmic app (versionCode=24, versionName=7.0) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record audio to external storage.

CVE-2019-17404
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Nokia IMPACT < 18A: allows full path disclosure

CVE-2019-15299
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.

CVE-2019-17124
Software Genérico General
N/A
UNKNOWN
EPSS
23.8%
2019 2 PoCs

Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

CVE-2019-8352
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2019 1 PoC

By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.