6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-3586
McAfee Endpoint Security (ENS) Networking
7.5
HIGH
EPSS
0.3%
2019 CWE-693 1 PoC

Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious sites where the GTI reputation is carefully manipulated and does not correctly trigger the ENS Firewall to block the connection.

CVE-2019-5055
N300 WNR2000v5 Networking
7.5
HIGH
EPSS
1.4%
2019 CWE-476 1 PoC

An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in an invalid sequence to the <WFAWLANConfig:1#PutMessage> service can cause a null pointer dereference, resulting in the hostapd service crashing. An unauthenticated attacker can send a specially-crafted SOAP request to trigger this vulnerability.

CVE-2019-3622
Data Loss Prevention (DLPe) for Windows Windows
7.5
HIGH
EPSS
0.1%
2019 CWE-552 1 PoC

Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.

CVE-2019-1429
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
83.0%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

CVE-2019-10174
infinispan General
7.5
HIGH
EPSS
0.9%
2019 CWE-470 1 PoC

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

CVE-2019-5037
Nest Labs General
7.5
HIGH
EPSS
0.1%
2019 CWE-190 1 PoC

An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.

CVE-2019-15993
Cisco Small Business 250 Series Smart Switches Software Web Networking
7.5
HIGH
EPSS
12.3%
2019 CWE-16 1 PoC

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.

CVE-2019-3628
McAfee Enterprise Security Manager (ESM) General
7.5
HIGH
EPSS
0.8%
2019 1 PoC

Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control.

CVE-2019-5137
Moxa General
7.5
HIGH
EPSS
0.5%
2019 CWE-321 1 PoC

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

CVE-2019-9514
Software Genérico Web
7.5
HIGH
EPSS
9.5%
2019 CWE-400 3 PoCs

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

CVE-2019-3636
McAfee Total Protection Windows
7.5
HIGH
EPSS
0.1%
2019 1 PoC

A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.

CVE-2019-10936
Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller General
7.5
HIGH
EPSS
2.0%
2019 CWE-400 1 PoC

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

CVE-2019-25073
github.com/goadesign/goa General
7.5
HIGH
EPSS
0.6%
2019 1 PoC

Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.

CVE-2019-14818
dpdk DevOps
7.5
HIGH
EPSS
1.1%
2019 CWE-401 1 PoC

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

CVE-2019-13608
🔥 KEV Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
71.3%
2019 0 PoCs

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVE-2019-9564
Cam Pan v2 General
7.5
HIGH
EPSS
0.4%
2019 1 PoC

A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

CVE-2019-5091
LEADTOOLS libltdic.so General
7.5
HIGH
EPSS
0.4%
2019 CWE-835 1 PoC

An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an infinite loop, resulting in a denial of service. An attacker can send a packet to trigger this vulnerability.

CVE-2019-0028
Junos OS Networking
7.5
HIGH
EPSS
0.6%
2019 CWE-404 1 PoC

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process to crash and restart. By simulating a specific BGP session restart, an attacker can repeatedly crash the RPD process causing prolonged denial of service (DoS). Graceful restart helper mode for BGP is enabled by default. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos

CVE-2019-5188
E2fsprogs General
7.5
HIGH
EPSS
0.1%
2019 CWE-787 1 PoC

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

CVE-2019-9099
Software Genérico General
7.5
HIGH
EPSS
9.1%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).