3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-25285
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.

CVE-2020-27403
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows an attacker on the adjacent network to arbitrarily browse and download sensitive files over an insecure web server running on port 7989 that lists all files & directories. An unprivileged remote attacker on the adjacent network, can download most system files, leading to serious critical information disclosure. Also, some TV models and/or FW versions may expose the webserver with the entire filesystem accessible on another port. For examp

CVE-2020-0516
Intel(R) Graphics Drivers General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12857
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe.

CVE-2020-0114
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 8 PoCs

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

CVE-2020-11452
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the file:// stream wrapper.

CVE-2020-23886
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree.

CVE-2020-11691
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.

CVE-2020-27181
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.

CVE-2020-28840
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).

CVE-2020-22054
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.

CVE-2020-7672
mosc General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution.

CVE-2020-3660
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA6574AU, QCS405, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, S

CVE-2020-19419
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.

CVE-2020-12856
Software Genérico General
N/A
UNKNOWN
EPSS
10.8%
2020 3 PoCs

OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.

CVE-2020-13121
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 0 PoCs

Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

CVE-2020-10173
Software Genérico General
N/A
UNKNOWN
EPSS
56.1%
2020 1 PoC

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

CVE-2020-24876
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.

CVE-2020-27602
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

CVE-2020-11863
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).