208 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2020-15917
Software Genérico Cloud
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

CVE-2020-27158
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
10.7%
2020 2 PoCs

Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.

CVE-2020-9363
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.

CVE-2020-26144
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

CVE-2020-28646
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.

CVE-2020-28341
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID is SVE-2020-18632 (November 2020).

CVE-2020-24333
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

CVE-2020-8189
Desktop Client Web Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-79 2 PoCs

A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.