3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26515
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.

CVE-2020-16158
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

GoPro gpmf-parser through 1.5 has a stack out-of-bounds write vulnerability in GPMF_ExpandComplexTYPE(). Parsing malicious input can result in a crash or potentially arbitrary code execution.

CVE-2020-15027
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.

CVE-2020-12120
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.

CVE-2020-25212
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

CVE-2020-19716
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).

CVE-2020-16225
Delta Electronics TPEditor General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-123 1 PoC

Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-17368
Software Genérico General
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

CVE-2020-27787
upx General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-119 1 PoC

A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

CVE-2020-12116
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2020 1 PoC

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

CVE-2020-7959
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception message if the database does not exist.

CVE-2020-10854
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Kernel stack addresses are leaked to userspace. The Samsung ID is SVE-2019-16161 (January 2020).

CVE-2020-10942
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

CVE-2020-14029
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files.

CVE-2020-8680
Intel(R) Graphics Drivers Advisory General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24711
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

CVE-2020-0566
Intel(R) TXE General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-24645
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-12821
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

CVE-2020-24999
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.