1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25328
XnConvert General
6.7
MEDIUM
EPSS
0.0%
2019 CWE-121 1 PoC

XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registration code field to trigger an application crash.

CVE-2019-25330
SurfOffline Professional General
6.7
MEDIUM
EPSS
0.0%
2019 CWE-121 1 PoC

SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trigger a denial of service condition and overwrite SEH registers.

CVE-2019-1649
Cisco Routers Networking
6.7
MEDIUM
EPSS
0.4%
2019 CWE-284 1 PoC

A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying

CVE-2019-25464
InputMapper General
6.7
MEDIUM
EPSS
0.0%
2019 CWE-770 1 PoC

InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an excessively long string. Attackers can trigger a denial of service by copying a large payload into the username field and double-clicking to process it, causing the application to crash.

CVE-2019-3667
McAfee TechCheck Windows
6.6
MEDIUM
EPSS
0.1%
2019 1 PoC

DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.

CVE-2019-14897
kernel General
6.6
MEDIUM
EPSS
0.3%
2019 CWE-121 6 PoCs

A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.

CVE-2019-15257
Cisco SPA112 2-Port Phone Adapter Networking
6.5
MEDIUM
EPSS
0.5%
2019 CWE-200 1 PoC

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper restrictions on configuration information. An attacker could exploit this vulnerability by sending a request to an affected device through the web-based management interface. A successful exploit could allow the attacker to return running configuration information that could also include sensitive information.

CVE-2019-10131
ImageMagick General
6.5
MEDIUM
EPSS
0.1%
2019 CWE-193 1 PoC

An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

CVE-2019-9900
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2019 1 PoC

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.

CVE-2019-3474
Filr General
6.5
MEDIUM
EPSS
3.3%
2019 CWE-22 1 PoC

A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

CVE-2019-5020
Yara Object General
6.5
MEDIUM
EPSS
0.3%
2019 CWE-617 1 PoC

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.

CVE-2019-19001
eSOMS Web
6.5
MEDIUM
EPSS
0.4%
2019 CWE-16 1 PoC

For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.

CVE-2019-3739
RSA BSAFE Crypto-J General
6.5
MEDIUM
EPSS
1.2%
2019 CWE-310 6 PoCs

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.

CVE-2019-10800
codecov General
6.5
MEDIUM
EPSS
0.3%
2019 1 PoC

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

CVE-2019-13988
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2019 1 PoC

Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).

CVE-2019-8988
TIBCO Data Science for AWS Web Cloud
6.5
MEDIUM
EPSS
0.2%
2019 1 PoC

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site contains a vulnerability that theoretically allows a user to escalate their privileges on the affected system, in a way that may allow for data modifications and deletions that should be denied. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVE-2019-5591
🔥 KEV Fortinet FortiOS Networking Windows ⚡ nuclei
6.5
MEDIUM
EPSS
48.4%
2019 0 PoCs

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

CVE-2019-3662
Advanced Threat Defense (ATD) Web
6.5
MEDIUM
EPSS
0.3%
2019 1 PoC

Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.

CVE-2019-11049
PHP Web Windows
6.5
MEDIUM
EPSS
2.8%
2019 CWE-415 1 PoC

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

CVE-2019-5786
🔥 KEV Chrome General
6.5
MEDIUM
EPSS
89.4%
2019 1 PoC

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.