6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25271
Data Backup Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.

CVE-2019-25304
Intelligent Security System SecurOS Enterprise General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\ISS\SecurOS\ to insert malicious code that would execute with system-level permissions during service startup.

CVE-2019-25269
Amiti Antivirus Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges by placing executable files in specific directory locations.

CVE-2019-25344
MobileGo General
8.5
HIGH
EPSS
0.0%
2019 CWE-732 1 PoC

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators group with full system access.

CVE-2019-25310
ActiveFax Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated administrative privileges.

CVE-2019-25679
RealTerm: Serial Terminal General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.

CVE-2019-25281
NCP_Secure_Entry_Client Windows
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-25287
Adaware Web Companion version General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2019-25305
JumpStart Web
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.

CVE-2019-25331
AVS Audio Converter General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a specially designed text file with 264 bytes of padding followed by register overwrite values to compromise the application and potentially execute arbitrary code.

CVE-2019-25327
Prime95 General
8.4
HIGH
EPSS
0.3%
2019 CWE-122 1 PoC

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.

CVE-2019-25360
Aida64 General
8.4
HIGH
EPSS
0.3%
2019 CWE-121 1 PoC

Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers can exploit the vulnerability by creating a malformed log file with carefully constructed SEH (Structured Exception Handler) overwrite techniques to achieve remote code execution.

CVE-2019-25365
ChaosPro Windows
8.4
HIGH
EPSS
0.3%
2019 CWE-121 1 PoC

ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious configuration file with carefully constructed payload to overwrite memory and gain remote code execution on vulnerable Windows XP systems.

CVE-2019-25336
Nsauditor SpotAuditor General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 2 PoCs

SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system.

CVE-2019-20459
Software Genérico General
8.4
HIGH
EPSS
0.0%
2019 1 PoC

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling the network card or changing the DNS servers.

CVE-2019-25321
FTP Navigator General
8.4
HIGH
EPSS
0.5%
2019 CWE-121 3 PoCs

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command textbox, enabling remote code execution and launching the calculator as proof of concept.

CVE-2019-25232
NetPCLinker General
8.4
HIGH
EPSS
0.0%
2019 CWE-120 1 PoC

NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a new client.

CVE-2019-25319
Domain Quester Pro General
8.4
HIGH
EPSS
0.3%
2019 CWE-121 1 PoC

Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.

CVE-2019-25357
Control Center PRO Windows
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on vulnerable Windows systems.

CVE-2019-25318
AVS Audio Converter General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 2 PoCs

AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.