Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2019-06-20 CVE-2019-3735 Improper Privilege Management vulnerability in Dell products
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability.
local
low complexity
dell CWE-269
7.8
2019-06-20 CVE-2019-8459 Unquoted Search Path or Element vulnerability in Checkpoint products
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path.
network
low complexity
checkpoint CWE-428
7.5
2019-06-20 CVE-2019-6962 OS Command Injection vulnerability in Rdkcentral Rdkb Ccsppandm Rdkb201812171
A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-20181217-1 CcspWifiAgent module allows attackers with login credentials to execute arbitrary shell commands under the CcspWifiSsp process (running as root) if the platform was compiled with the ENABLE_FEATURE_MESHWIFI macro.
network
rdkcentral CWE-78
8.5
2019-06-20 CVE-2019-1879 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-78
7.2
2019-06-20 CVE-2019-1878 OS Command Injection vulnerability in Cisco Telepresence CE and Telepresence TC
A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, adjacent attacker to inject arbitrary shell commands that are executed by the device.
low complexity
cisco CWE-78
8.3
2019-06-20 CVE-2019-1625 Unspecified vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user on an affected device.
local
low complexity
cisco
7.2
2019-06-20 CVE-2019-1623 OS Command Injection vulnerability in Cisco Meeting Server
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user.
local
low complexity
cisco CWE-78
7.2
2019-06-19 CVE-2019-12899 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Devicenet Builder 2.04
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.
network
low complexity
deltaww CWE-119
7.5
2019-06-19 CVE-2019-12898 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Devicenet Builder 2.04
Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.
network
low complexity
deltaww CWE-119
7.5
2019-06-19 CVE-2019-2025 Use After Free vulnerability in Google Android
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking.
local
low complexity
google CWE-416
7.2