3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-19771
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.

CVE-2019-15051
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2019 1 PoC

An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.

CVE-2019-10873
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

CVE-2019-19204
Software Genérico General
N/A
UNKNOWN
EPSS
8.9%
2019 2 PoCs

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

CVE-2019-20535
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devices can be established from the lock screen. The Samsung ID is SVE-2019-15533 (December 2019).

CVE-2019-15406
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ASUS_X00LD_3 Android device with a build fingerprint of asus/WW_Phone/ASUS_X00LD_3:7.1.1/NMF26F/14.0400.1806.203-20180720:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-i

CVE-2019-15332
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.

CVE-2019-10513
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM89

CVE-2019-1083
Microsoft .NET Framework 4.5.2 General
N/A
UNKNOWN
EPSS
10.6%
2019 1 PoC

A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.

CVE-2019-19782
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.

CVE-2019-6442
Software Genérico General
N/A
UNKNOWN
EPSS
10.2%
2019 2 PoCs

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

CVE-2019-16413
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() infinite loop and denial of service on SMP systems.

CVE-2019-0380
SAP Landscape Management enterprise edition General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.

CVE-2019-15657
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.

CVE-2019-14496
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.

CVE-2019-10803
push-dir General
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an attacker to inject arbitrary commands.

CVE-2019-18412
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

JetBrains IDETalk plugin before version 193.4099.10 allows XXE

CVE-2019-20184
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

KeePass 2.4.1 allows CSV injection in the title field of a CSV export.

CVE-2019-9809
Firefox General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These messages cannot be immediately dismissed, allowing for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.

CVE-2019-14208
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NULL pointer dereference and crash when getting a PDF object from a document, or parsing a certain portfolio that contains a null dictionary.