794 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25321
FTP Navigator General
8.4
HIGH
EPSS
0.5%
2019 CWE-121 3 PoCs

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command textbox, enabling remote code execution and launching the calculator as proof of concept.

CVE-2019-25365
ChaosPro Windows
8.4
HIGH
EPSS
0.3%
2019 CWE-121 1 PoC

ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory and gain remote code execution on vulnerable Windows XP systems.

CVE-2019-25331
AVS Audio Converter General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a specially designed text file with 264 bytes of padding followed by register overwrite values to compromise the application and potentially execute arbitrary code.

CVE-2019-25360
Aida64 General
8.4
HIGH
EPSS
0.3%
2019 CWE-121 1 PoC

Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers can exploit the vulnerability by creating a malformed log file with carefully constructed SEH (Structured Exception Handler) overwrite techniques to achieve remote code execution.

CVE-2019-25363
WMV to AVI MPEG DVD WMV Convertor General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the application by providing an oversized license input. Attackers can generate a 6000-byte payload and paste it into the 'License Name and License Code' field to trigger an application crash.

CVE-2019-20741
Software Genérico General
8.4
HIGH
EPSS
0.3%
2019 1 PoC

NETGEAR WAC510 devices before 5.0.10.2 are affected by disclosure of sensitive information.

CVE-2019-3660
Advanced Threat Defense (ATD) Web
8.4
HIGH
EPSS
0.7%
2019 1 PoC

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.

CVE-2019-3629
McAfee Enterprise Security Manager (ESM) General
8.3
HIGH
EPSS
1.2%
2019 1 PoC

Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters.

CVE-2019-20760
Software Genérico General
8.3
HIGH
EPSS
0.2%
2019 1 PoC

NETGEAR R9000 devices before 1.0.4.26 are affected by authentication bypass.

CVE-2019-20361
Software Genérico Web Database Windows
8.3
HIGH
EPSS
28.1%
2019 3 PoCs

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

CVE-2019-11540
Software Genérico General
8.3
HIGH
EPSS
6.3%
2019 1 PoC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

CVE-2019-17094
Belkin WeMo Insight Switch Web
8.3
HIGH
EPSS
0.2%
2019 CWE-121 1 PoC

A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions.

CVE-2019-10761
vm2 General
8.3
HIGH
EPSS
0.8%
2019 2 PoCs

This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.

CVE-2019-16536
DB General
8.2
HIGH
EPSS
0.3%
2019 CWE-120 1 PoC

Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

CVE-2019-3612
Data eXchange Layer (DXL) Platform Windows
8.2
HIGH
EPSS
0.0%
2019 1 PoC

Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text via the GUI or command line.

CVE-2019-10185
icedtea-web General
8.2
HIGH
EPSS
1.9%
2019 CWE-22 2 PoCs

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVE-2019-10182
icedtea-web General
8.2
HIGH
EPSS
1.1%
2019 CWE-22 2 PoCs

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

CVE-2019-20734
Software Genérico General
8.2
HIGH
EPSS
0.5%
2019 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.40, D8500 before 1.0.3.39, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.22, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150v1 before 1.0.0.42, EX6200 before 1.0.3.88, EX7000 before 1.0.0.66, R6300v2 before 1.0.4.18, R6400 before 1.0.1.24, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6700v3 before 1.0.2.32, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R6900P before 1.0.0.56, R7000P before 1.0.0.56, R7100LG before 1.0.

CVE-2019-5040
Nest Labs General
8.2
HIGH
EPSS
0.1%
2019 CWE-190 1 PoC

An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.

CVE-2019-18426
🔥 KEV WhatsApp Desktop Web
8.2
HIGH
EPSS
61.0%
2019 CWE-79 3 PoCs

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.