3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-12803
LibreOffice General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to m

CVE-2020-28279
flattenizer General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-8946
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.

CVE-2020-10532
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.

CVE-2020-27374
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

CVE-2020-15868
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.

CVE-2020-14393
perl-dbi General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-121 2 PoCs

A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.

CVE-2020-8220
Pulse Connect Secure General
N/A
UNKNOWN
EPSS
5.0%
2020 CWE-400 1 PoC

A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.

CVE-2020-21050
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.

CVE-2020-14322
Moodle General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-770 1 PoC

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVE-2020-29043
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

CVE-2020-7457
FreeBSD General
N/A
UNKNOWN
EPSS
44.6%
2020 1 PoC

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.

CVE-2020-27209
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversary to extract the private ECC key.

CVE-2020-5807
Rockwell FactoryTalk Diagnostics General
N/A
UNKNOWN
EPSS
4.2%
2020 1 PoC

An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.

CVE-2020-18775
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.

CVE-2020-5761
Grandstream HT800 Series General
N/A
UNKNOWN
EPSS
3.9%
2020 CWE-835 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.

CVE-2020-6613
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

CVE-2020-10853
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are SVE-2019-16010, SVE-2019-16011, SVE-2019-16012 (January 2020).

CVE-2020-13835
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).

CVE-2020-21602
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.