3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-21997
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 3 PoCs

Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information resulting in authentication bypass, session hijacking and full system control.

CVE-2020-7663
websocket-extensions (ruby) General
N/A
UNKNOWN
EPSS
2.6%
2020 2 PoCs

websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVE-2020-6920
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-7465
MPD: FreeBSD PPP daemon General
N/A
UNKNOWN
EPSS
3.0%
2020 CWE-787 1 PoC

The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).

CVE-2020-25207
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.

CVE-2020-15352
Software Genérico General
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVE-2020-10009
macOS General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.

CVE-2020-13224
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow

CVE-2020-6612
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.

CVE-2020-7630
git-add-remote General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.

CVE-2020-3638
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'An Unaligned address or size can propagate to the database due to improper page permissions and can lead to improper access control' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Agatti, Bitra, Kamorta, QCA6390, QCS404, QCS610, Rennell, SA515M, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

CVE-2020-11256
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Memory corruption due to lack of check of validation of pointer to buffer passed to trustzone in Snapdragon Wired Infrastructure and Networking

CVE-2020-6806
Thunderbird General
N/A
UNKNOWN
EPSS
2.6%
2020 2 PoCs

By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVE-2020-28276
deep-set General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-26600
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with Q(10.0) software. Auto Hotspot allows attackers to obtain sensitive information. The Samsung ID is SVE-2020-17288 (October 2020).

CVE-2020-14928
Software Genérico General
N/A
UNKNOWN
EPSS
6.4%
2020 1 PoC

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

CVE-2020-28641
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.

CVE-2020-27349
aptdaemon General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-862 1 PoC

Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.

CVE-2020-15816
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.

CVE-2020-12961
2nd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-20 1 PoC

A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.