Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2019-10051 An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs error condition and ... | N/A | NONE | β | 0 |
| CVE-2019-10052 An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. At this point, the Rust environment runs into a pan... | N/A | NONE | β | 0 |
| CVE-2019-14694 A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifil... | N/A | NONE | β | 0 |
| CVE-2019-10054 An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nf... | N/A | NONE | β | 0 |
| CVE-2019-10055 An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file. | N/A | NONE | β | 0 |
| CVE-2019-10056 An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function DecodeEthernet in decode-ethernet.c is executed a second... | N/A | NONE | β | 0 |
| CVE-2019-15753 In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both ... | N/A | NONE | β | 0 |
| CVE-2019-10057 Various Lexmark products have CSRF. | N/A | NONE | β | 0 |
| CVE-2019-10059 The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices. | N/A | NONE | β | 0 |
| CVE-2019-9930 Various Lexmark products have an Integer Overflow. | N/A | NONE | β | 0 |
| CVE-2019-9931 Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device. | N/A | NONE | β | 0 |
| CVE-2019-13349 In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes. | N/A | NONE | β | 0 |
| CVE-2019-9933 Various Lexmark products have a Buffer Overflow (issue 3 of 3). | N/A | NONE | β | 0 |
| CVE-2017-18594 nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-method... | N/A | NONE | β | 0 |
| CVE-2019-10724 There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected pro... | N/A | NONE | β | 0 |
| CVE-2017-14201 Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prio... | N/A | NONE | β | 0 |
| CVE-2017-14202 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrar... | N/A | NONE | β | 0 |
| CVE-2019-11060 The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very s... | 7.5 | HIGH | β | 0 |
| CVE-2019-11061 A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/sma... | N/A | NONE | β | 0 |
| CVE-2019-11063 A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and con... | N/A | NONE | β | 0 |
| CVE-2019-11064 A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administratorβs ... | 9.8 | CRITICAL | β | 0 |
| CVE-2019-11245 In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If... | N/A | NONE | β | 0 |
| CVE-2018-21007 The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads. | N/A | NONE | β | 0 |
| CVE-2019-11246 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over th... | 6.5 | MEDIUM | β | 0 |
| CVE-2019-11247 The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this m... | 8.1 | HIGH | β | 0 |
| CVE-2019-11248 The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially ... | 8.2 | HIGH | β | 0 |
| CVE-2019-11249 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over th... | 6.5 | MEDIUM | β | 0 |
| CVE-2019-14278 In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page. | N/A | NONE | β | 0 |
| CVE-2019-11250 The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as... | 6.5 | MEDIUM | β | 0 |
| CVE-2019-13405 A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any aut... | N/A | NONE | β | 0 |
| CVE-2019-13406 A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication. | N/A | NONE | β | 0 |
| CVE-2019-13407 A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error... | N/A | NONE | β | 0 |
| CVE-2019-14943 An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials. | N/A | NONE | β | 0 |
| CVE-2019-13408 A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without an... | 7.5 | HIGH | β | 0 |
| CVE-2019-15757 libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c. | N/A | NONE | β | 0 |
| CVE-2019-5530 Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature. | N/A | NONE | β | 0 |
| CVE-2019-15758 An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-ser... | 6.5 | MEDIUM | β | 0 |
| CVE-2019-15759 An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can cause... | 6.5 | MEDIUM | β | 0 |
| CVE-2019-15767 In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file. | N/A | NONE | β | 0 |
| CVE-2019-15769 The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. | N/A | NONE | β | 0 |
| CVE-2019-15770 The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. | N/A | NONE | β | 0 |
| CVE-2019-15772 The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | N/A | NONE | β | 0 |
| CVE-2019-15773 The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | N/A | NONE | β | 0 |
| CVE-2019-15774 The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | N/A | NONE | β | 0 |
| CVE-2019-15775 The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | N/A | NONE | β | 0 |
| CVE-2018-15513 Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role. | N/A | NONE | β | 0 |
| CVE-2019-15776 The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. | N/A | NONE | β | 0 |
| CVE-2019-15777 The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS. | N/A | NONE | β | 0 |
| CVE-2019-15780 The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | 9.8 | CRITICAL | β | 0 |
| CVE-2019-14524 An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than ... | 7.8 | HIGH | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.