3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26117
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.

CVE-2020-15821
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

CVE-2020-6793
Thunderbird General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5.

CVE-2020-28332
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally signed firmware updates and is susceptible to processing and installing modified/malicious images.

CVE-2020-8438
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

CVE-2020-15682
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

CVE-2020-21594
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file.

CVE-2020-16155
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.

CVE-2020-35534
LibRaw General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-400 1 PoC

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.

CVE-2020-7039
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

CVE-2020-13826
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.

CVE-2020-11147
Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-15389
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.

CVE-2020-35556
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.

CVE-2020-21827
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.

CVE-2020-15653
Firefox ESR General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVE-2020-10223
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

CVE-2020-13814
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.

CVE-2020-18898
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

CVE-2020-8221
Pulse Connect Secure General
N/A
UNKNOWN
EPSS
2.1%
2020 CWE-22 1 PoC

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.