3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-6609
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

CVE-2020-12352
BlueZ General
N/A
UNKNOWN
EPSS
2.4%
2020 2 PoCs

Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

CVE-2020-25645
kernel General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-319 1 PoC

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.

CVE-2020-11123
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8009W, APQ8017, APQ8037, APQ8053, APQ8064AU, APQ8096, APQ8096AU, APQ8096SG, APQ8098, MDM8207, MDM9150, MDM92

CVE-2020-10793
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with the CodeIgniter framework but that CodeIgniter is not responsible for introducing this issue because the framework has never provided a login screen, nor any kind of login or user management facilities beyond a Session library. Also, another reporter indicates the issue is with a cu

CVE-2020-7907
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

CVE-2020-7545
EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-284 1 PoC

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.

CVE-2020-25204
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of this broadcast receiver is to show an in-game push notification to the player. However, the application does not enforce any authorization schema on the broadcast receiver, allowing any application to send fully customizable in-game push notifications.

CVE-2020-24385
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compat/linux/linux_emul.h is not getting initialized and returns NULL from em_find().

CVE-2020-6584
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Nagios Log Server 2.1.3 has Incorrect Access Control.

CVE-2020-24038
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

CVE-2020-28574
Trend Micro Worry-Free Business Security General
N/A
UNKNOWN
EPSS
4.0%
2020 1 PoC

A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.

CVE-2020-22024
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.

CVE-2020-25685
dnsmasq General
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-326 2 PoCs

A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the

CVE-2020-16849
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated network attacker, may expose Sensitive Information.

CVE-2020-15871
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 3 PoCs

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

CVE-2020-13626
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

CVE-2020-14362
xorg-x11-server General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-191 1 PoC

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-16288
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.