9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-13579
Softmaker Software General
8.8
HIGH
EPSS
3.8%
2020 CWE-190 1 PoC

An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser perform arithmetic that may overflow which can result in an undersized heap allocation. Later when copying data from the file into this allocation, a heap-based buffer overflow will occur which can corrupt memory. These types of memory corruptions can allow for code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulner

CVE-2020-6092
Nitro Pro General
8.8
HIGH
EPSS
0.2%
2020 CWE-190 1 PoC

An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order to trigger this vulnerability, victim must open a malicious file.

CVE-2020-26909
Software Genérico General
8.8
HIGH
EPSS
0.4%
2020 1 PoC

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3.48.

CVE-2020-6149
Pixar General
8.8
HIGH
EPSS
0.2%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file in an instance in USDC file format PATHS section.

CVE-2020-13552
Advantech General
8.8
HIGH
EPSS
0.1%
2020 CWE-276 1 PoC

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

CVE-2020-16009
🔥 KEV Chrome General
8.8
HIGH
EPSS
84.4%
2020 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-13543
Webkit General
8.8
HIGH
EPSS
1.5%
2020 2 PoCs

A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVE-2020-6155
Pixar General
8.8
HIGH
EPSS
1.5%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 while parsing compressed value rep arrays in binary USD files. A specially crafted malformed file can trigger a heap overflow, which can result in remote code execution. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.

CVE-2020-4436
Aspera Faspex On Demand General
8.8
HIGH
EPSS
0.4%
2020 1 PoC

Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.

CVE-2020-28595
Prusa Research General
8.8
HIGH
EPSS
0.4%
2020 CWE-122 2 PoCs

An out-of-bounds write vulnerability exists in the Obj.cpp load_obj() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted obj file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-6150
Pixar General
8.8
HIGH
EPSS
0.2%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software USDC file format SPECS section decompression heap overflow.

CVE-2020-4107
HCL Domino General
8.8
HIGH
EPSS
0.0%
2020 CWE-284 1 PoC

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.

CVE-2020-13515
NZXT General
8.8
HIGH
EPSS
0.0%
2020 CWE-269 2 PoCs

A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause an adversary to obtain elevated privileges. An attacker can send a malicious IRP to trigger this vulnerability.

CVE-2020-27250
SoftMaker General
8.8
HIGH
EPSS
0.3%
2020 CWE-122 2 PoCs

In SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow at Version/Instance 0x0005 and 0x0016. An attacker can entice the victim to open a document to trigger this vulnerability.

CVE-2020-9306
Software Genérico General
8.8
HIGH
EPSS
0.2%
2020 2 PoCs

Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.

CVE-2020-28598
Prusa Research General
8.8
HIGH
EPSS
0.4%
2020 CWE-122 2 PoCs

An out-of-bounds write vulnerability exists in the Admesh stl_fix_normal_directions() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted AMF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-13580
Softmaker Software General
8.8
HIGH
EPSS
3.8%
2020 CWE-787 1 PoC

An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser to explicitly trust a length from a particular record type and use it to write a 16-bit null relative to a buffer allocated on the stack. Due to a lack of bounds-checking on this value, this can allow an attacker to write to memory outside of the buffer and controllably corrupt memory. This can allow an attacker to earn code execution under the context of the application. An at

CVE-2020-6156
Pixar General
8.8
HIGH
EPSS
0.2%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file in an instance USDC file format path element token index.

CVE-2020-13558
Webkit General
8.8
HIGH
EPSS
0.6%
2020 CWE-416 1 PoC

A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.