3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-6584
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Nagios Log Server 2.1.3 has Incorrect Access Control.

CVE-2020-9973
macOS General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

CVE-2020-24038
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

CVE-2020-28574
Trend Micro Worry-Free Business Security General
N/A
UNKNOWN
EPSS
4.0%
2020 1 PoC

A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.

CVE-2020-22024
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.

CVE-2020-25685
dnsmasq General
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-326 2 PoCs

A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the

CVE-2020-16849
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated network attacker, may expose Sensitive Information.

CVE-2020-15871
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 3 PoCs

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

CVE-2020-13626
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

CVE-2020-14362
xorg-x11-server General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-191 1 PoC

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-16288
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-11138
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-6954
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_folder.cgi?apply_mode=ping_server URI.

CVE-2020-20276
Software Genérico General
N/A
UNKNOWN
EPSS
4.6%
2020 1 PoC

An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.

CVE-2020-22021
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.

CVE-2020-24716
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.

CVE-2020-12891
Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

CVE-2020-6918
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-25564
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature.