6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-7141
Adobe Acrobat and Reader General
N/A
UNKNOWN
EPSS
9.3%
2019 1 PoC

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

CVE-2019-9839
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.

CVE-2019-15084
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.

CVE-2019-10661
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

CVE-2019-7147
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can cause segmentation faults, leading to denial-of-service.

CVE-2019-20859
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.

CVE-2019-11693
Thunderbird General
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVE-2019-14224
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution on the victim machine. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.

CVE-2019-11871
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.

CVE-2019-9575
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.

CVE-2019-15411
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ZenFone 3 Laser Android device with a build fingerprint of asus/WW_msm8937/msm8937:7.1.1/NMF26F/WW_32.40.106.114_20180928:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-i

CVE-2019-8273
UltraVNC General
N/A
UNKNOWN
EPSS
4.0%
2019 CWE-122 1 PoC

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1212.

CVE-2019-19735
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 3 PoCs

class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.

CVE-2019-16905
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

CVE-2019-15772
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVE-2019-16404
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

CVE-2019-14249
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service (division by zero) via an ELF file with a zero-size section group (SHT_GROUP), as demonstrated by dwarfdump.

CVE-2019-14494
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2019 2 PoCs

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

CVE-2019-20576
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).

CVE-2019-5366
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.