6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-15447
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Samsung S7 Edge Android device with a build fingerprint of samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

CVE-2019-5685
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access to a shader local temporary array, which may lead to denial of service or code execution.

CVE-2019-2437
Solaris Operating System Database
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2019-15428
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Xiaomi Mi Note 2 Android device with a build fingerprint of Xiaomi/scorpio/scorpio:6.0.1/MXB48T/7.1.5:user/release-keys contains a pre-installed app with a package name of com.miui.powerkeeper app (versionCode=40000, versionName=4.0.00) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.

CVE-2019-15062
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

CVE-2019-2987
Java Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the Java SE product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted

CVE-2019-15370
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Haier G8 Android device with a build fingerprint of Haier/HM-G559-FL/G8:8.1.0/O11019/1526527761:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

CVE-2019-14471
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

TestLink 1.9.19 has XSS via the error.php message parameter.

CVE-2019-9039
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. The _all_docs endpoint is not required for Couchbase Mobile replication and external access to this REST endpoint has been blocked to mitigate this issue. This issue has been f

CVE-2019-25041
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

CVE-2019-7432
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

PHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section.

CVE-2019-16736
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2019 1 PoC

A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrary code as the root user.

CVE-2019-17041
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMsg will reach the value zero and will skip the sanity check that detects invalid log messages. The message will then be considered valid, and the parser will eat up the nonexistent colon delimiter. In doing so, it will decrement lenMsg, a sig

CVE-2019-7254
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2019 1 PoC

Linear eMerge E3-Series devices allow File Inclusion.

CVE-2019-13097
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.

CVE-2019-5438
harp General
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-22 1 PoC

Path traversal using symlink in npm harp module versions <= 0.29.0.

CVE-2019-15598
treekill Windows
N/A
UNKNOWN
EPSS
3.8%
2019 CWE-94 1 PoC

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

CVE-2019-14546
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his email signature, which fires when the victim replies or forwards the mail, thus helping him steal victims' cookies (hence compromising their accounts).

CVE-2019-11511
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2019 1 PoC

Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.

CVE-2019-14082
Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9206, MDM9207C, MDM9607, QCN7605, SM8150