1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-4047
Jazz Reporting Service General
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.

CVE-2019-7306
byobu General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu

CVE-2019-25064
Core Portal General
4.3
MEDIUM
EPSS
0.1%
2019 CWE-352 1 PoC

A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. Upgrading to version 27.0.8 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2019-3823
curl General
4.3
MEDIUM
EPSS
1.9%
2019 CWE-125 3 PoCs

libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.

CVE-2019-18995
PB610 Panel Builder 600 Web
4.3
MEDIUM
EPSS
0.9%
2019 CWE-20 1 PoC

The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.

CVE-2019-18997
PB610 Panel Builder 600 General
4.3
MEDIUM
EPSS
0.4%
2019 CWE-424 1 PoC

The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.

CVE-2019-4722
Cognos Analytics General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.

CVE-2019-11206
TIBCO Spotfire Analytics Platform for AWS Marketplace Cloud
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains vulnerabilities that theoretically allow a malicious user to undermine the integrity of comments and bookmarks. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.2.0, and TIBCO Spotfire Server: versions up to and including 7.11.2; 7.12.0; 7.13.0; 7.14.0; 10.0.0; 10.0.1; 10.1.0; and 10.2.0.

CVE-2019-4334
Cognos Analytics General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in future attacks against the system. IBM X-Force ID: 161271.

CVE-2019-13457
Software Genérico General
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search results to disclose information from their "company" tickets (with the same CustomerID), even when the CustomerDisableCompanyTicketAccess setting is turned on.

CVE-2019-6744
Knox DevOps Cloud
4.3
MEDIUM
EPSS
0.1%
2019 CWE-284 1 PoC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. Was ZDI-CAN-7381.

CVE-2019-19091
eSOMS Web
4.3
MEDIUM
EPSS
0.2%
2019 CWE-16 1 PoC

For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.

CVE-2019-3880
samba Web Windows
4.2
MEDIUM
EPSS
3.4%
2019 CWE-22 1 PoC

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.

CVE-2019-11269
Spring Security OAuth Web
4.2
MEDIUM
EPSS
6.6%
2019 CWE-601 2 PoCs

Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.

CVE-2019-1609
MDS 9000 Series Multilayer Switches Networking
4.2
MEDIUM
EPSS
0.3%
2019 CWE-77 2 PoCs

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit th

CVE-2019-11039
PHP Web
4.2
MEDIUM
EPSS
1.4%
2019 CWE-125 2 PoCs

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.

CVE-2019-20645
Software Genérico Web
4.2
MEDIUM
EPSS
0.3%
2019 1 PoC

NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.

CVE-2019-3828
Ansible DevOps
4.2
MEDIUM
EPSS
0.0%
2019 CWE-22 1 PoC

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

CVE-2019-16769
serialize-javascript Web
4.2
MEDIUM
EPSS
0.4%
2019 CWE-79 1 PoC

The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.

CVE-2019-3819
kernel: General
4.2
MEDIUM
EPSS
0.0%
2019 CWE-835 3 PoCs

A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.