6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-9228
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.

CVE-2019-12148
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into the device's admin web portal without providing any credentials. This affects /var/webconfig/gui/Webconfig.inc.php.

CVE-2019-19447
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2019 2 PoCs

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

CVE-2019-7259
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.

CVE-2019-13418
Search Guard General
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-311 1 PoC

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

CVE-2019-13636
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2019 2 PoCs

In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

CVE-2019-20807
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

CVE-2019-9055
Software Genérico Web
N/A
UNKNOWN
EPSS
32.0%
2019 1 PoC

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVE-2019-6729
Reader General
N/A
UNKNOWN
EPSS
0.7%
2019 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7423.

CVE-2019-15144
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.

CVE-2019-15809
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because the Atmel Toolbox 00.03.11.05 contains two versions of ECDSA signature functions, described as fast and secure, but the affected cards chose to use the fast version, which leaks the bit length of the random nonce via timing. This affects Athena IDProtect 010b.0352.000

CVE-2019-12169
Software Genérico Web
N/A
UNKNOWN
EPSS
75.4%
2019 2 PoCs

ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.

CVE-2019-12490
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.

CVE-2019-2531
MySQL Server Database
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2019-20819
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls for XML parsing.

CVE-2019-8931
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application.

CVE-2019-7793
Adobe Acrobat and Reader General
N/A
UNKNOWN
EPSS
2.9%
2019 1 PoC

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVE-2019-3972
Comodo Antivirus Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and contains a SharedMemoryDictionary object, which allows a low privileged process to modify the object data causing CmdAgent.exe to crash.

CVE-2019-13564
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

XSS exists in Ping Identity Agentless Integration Kit before 1.5.

CVE-2019-7431
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.