9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-6084
Allen-Bradley General
7.5
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability by sending an Electronic Key Segment with less bytes than required by the Key Format Table.

CVE-2020-7768
grpc General
7.5
HIGH
EPSS
1.3%
2020 4 PoCs

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

CVE-2020-11274
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-6071
Videolabs General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

CVE-2020-6111
Allen-Bradley General
7.5
HIGH
EPSS
0.1%
2020 CWE-189 1 PoC

An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 and Series B FRN 10.000. A specially crafted packet can cause a major error, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2020-4208
Spectrum Protect Plus General
7.5
HIGH
EPSS
0.1%
2020 1 PoC

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.

CVE-2020-37015
Ruijie Networks Switch eWeb S29_RGOS General
7.5
HIGH
EPSS
0.5%
2020 CWE-22 1 PoC

Ruijie Networks Switch eWeb S29_RGOS 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration files containing credentials and network settings.

CVE-2020-10067
zephyr General
7.5
HIGH
EPSS
0.1%
2020 CWE-190 1 PoC

A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers. The impact would depend on the underlying system call and can range from denial of service to information leak to memory corruption resulting in code execution within the kernel. See NCC-ZEP-005 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.

CVE-2020-6817
Mozilla Bleach General
7.5
HIGH
EPSS
0.6%
2020 1 PoC

bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}).

CVE-2020-13530
EIP Stack Group General
7.5
HIGH
EPSS
0.4%
2020 CWE-910 1 PoC

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2020-9050
Metasys Reporting Engine (MRE) Web Services versions 2.0 and 2.1 General
7.5
HIGH
EPSS
0.7%
2020 1 PoC

Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.

CVE-2020-7669
github.com/u-root/u-root/pkg/tarutil General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction.

CVE-2020-6208
SAP Business Objects Business Intelligence Platform (Crystal Reports) General
7.5
HIGH
EPSS
2.6%
2020 1 PoC

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.

CVE-2020-7742
simpl-schema General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

This affects the package simpl-schema before 1.10.2.

CVE-2020-36567
github.com/gin-gonic/gin General
7.5
HIGH
EPSS
0.5%
2020 1 PoC

Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.

CVE-2020-8782
Software Genérico General
7.5
HIGH
EPSS
8.4%
2020 1 PoC

Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

CVE-2020-7683
rollup-plugin-server General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.

CVE-2020-11279
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-12513
Comtrol IO-Link Master General
7.5
HIGH
EPSS
8.9%
2020 CWE-78 1 PoC

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.