9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7679
casperjs General
7.3
HIGH
EPSS
0.8%
2020 3 PoCs

In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.

CVE-2020-7778
systeminformation General
7.3
HIGH
EPSS
1.1%
2020 1 PoC

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.

CVE-2020-28441
conf-cfg-ini General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-7736
bmoor General
7.3
HIGH
EPSS
0.8%
2020 2 PoCs

The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

CVE-2020-28462
ion-parser General
7.3
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-4059
mversion General
7.3
HIGH
EPSS
2.1%
2020 CWE-77 1 PoC

In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This vulnerability is patched by version 2.0.0. Previous releases are deprecated in npm. As a workaround, make sure to escape git commit messages when using the commitMessage option for the update function.

CVE-2020-11263
Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
7.3
HIGH
EPSS
0.0%
2020 1 PoC

An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2020-1773
((OTRS)) Community Edition General
7.3
HIGH
EPSS
0.5%
2020 CWE-331 1 PoC

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

CVE-2020-7260
Mcafee Application and Change Control (MACC) General
7.3
HIGH
EPSS
0.1%
2020 CWE-264 1 PoC

DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

CVE-2020-28495
total.js General
7.3
HIGH
EPSS
6.1%
2020 1 PoC

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

CVE-2020-7737
safetydance General
7.3
HIGH
EPSS
0.4%
2020 2 PoCs

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

CVE-2016-15002
MONyog Ultimate General
7.3
HIGH
EPSS
0.3%
2016 CWE-269 1 PoC

A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.

CVE-2018-2408
SAP Business Objects General
7.3
HIGH
EPSS
0.2%
2018 1 PoC

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.

CVE-2018-1124
procps-ng General
7.3
HIGH
EPSS
0.5%
2018 CWE-190 6 PoCs

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.

CVE-2018-1122
procps-ng, procps General
7.3
HIGH
EPSS
0.3%
2018 CWE-829 3 PoCs

procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.

CVE-2018-15610
IP Office General
7.3
HIGH
EPSS
0.6%
2018 CWE-284 1 PoC

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

CVE-2018-4022
MKVToolNix General
7.3
HIGH
EPSS
0.7%
2018 1 PoC

A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.

CVE-2018-10877
kernel General
7.3
HIGH
EPSS
0.2%
2018 CWE-125 2 PoCs

Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.

CVE-2018-21094
Software Genérico General
7.3
HIGH
EPSS
0.3%
2018 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7, WND930 before 2.1.5, and WN604 before 3.3.10.

CVE-2018-12463
Fortify Software Security Center General
7.3
HIGH
EPSS
21.9%
2018 1 PoC

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.