3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-21602
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.

CVE-2020-35685
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.)

CVE-2020-13450
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.

CVE-2020-10569
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This may be a duplicate of CVE-2020-1938

CVE-2020-28025
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2020 1 PoC

Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process memory.

CVE-2020-0240
Android General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594

CVE-2020-28395
SCALANCE X-200RNA switch family General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-321 1 PoC

A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

CVE-2020-19038
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

File Deletion vulnerability in Halo 0.4.3 via delBackup.

CVE-2020-25746
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility.

CVE-2020-24618
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

CVE-2020-12110
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

CVE-2020-8636
Software Genérico General
N/A
UNKNOWN
EPSS
4.7%
2020 2 PoCs

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

CVE-2020-11490
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_country, or cert_email parameter.

CVE-2020-8147
utils-extend General
N/A
UNKNOWN
EPSS
1.1%
2020 CWE-471 1 PoC

Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.

CVE-2020-24490
BlueZ Advisory General
N/A
UNKNOWN
EPSS
4.5%
2020 2 PoCs

Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.

CVE-2020-8959
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.

CVE-2020-6484
Chrome General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.

CVE-2020-13253
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.

CVE-2020-27625
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.