3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-3660
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA6574AU, QCS405, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, S

CVE-2020-19419
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.

CVE-2020-12856
Software Genérico General
N/A
UNKNOWN
EPSS
10.8%
2020 3 PoCs

OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.

CVE-2020-13121
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 0 PoCs

Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

CVE-2020-10173
Software Genérico General
N/A
UNKNOWN
EPSS
56.1%
2020 1 PoC

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

CVE-2020-24876
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.

CVE-2020-10787
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).

CVE-2020-22017
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.

CVE-2020-36024
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVE-2020-6509
Chrome General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVE-2020-12608
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2020 3 PoCs

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.

CVE-2020-27602
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

CVE-2020-11863
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).

CVE-2020-11723
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

CVE-2020-15775
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.

CVE-2020-26977
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

CVE-2020-16169
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, granting audio, video, and motor control via unspecified vectors.

CVE-2020-0533
Intel(R) CSME General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

CVE-2020-26557
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).

CVE-2020-25374
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.