Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2019
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X-Force ID: 156001.
CVSS Score
6.3
EPSS Score
0.001
Published
2019-03-22
IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.
CVSS Score
8.2
EPSS Score
0.007
Published
2019-03-22
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
CVSS Score
5.3
EPSS Score
0.203
Published
2019-03-22
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-03-22
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
CVSS Score
7.8
EPSS Score
0.003
Published
2019-03-22
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-03-22
Caret before 2019-02-22 allows Remote Code Execution.
CVSS Score
9.8
EPSS Score
0.087
Published
2019-03-22
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
CVSS Score
7.5
EPSS Score
0.047
Published
2019-03-22
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
CVSS Score
7.5
EPSS Score
0.031
Published
2019-03-22
The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to download arbitrary files from the device including contacts, photos, videos, sound clips, etc. The attacker must be authenticated as a "recognized device."
CVSS Score
5.3
EPSS Score
0.002
Published
2019-03-22


Contact Us

Shodan ® - All rights reserved