3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-12891
Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

CVE-2020-6918
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-11164
Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'Third-party app may also call the broadcasts in Perfdump and cause privilege escalation issue due to improper access control' in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in Agatti, APQ8096AU, APQ8098, Bitra, Kamorta, MSM8909W, MSM8917, MSM8940, Nicobar, QCA6390, QCM2150, QCS605, Rennell, SA6155P, SA8155P, Saipan, SDA660, SDM429W, SDM450, SDM630, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

CVE-2020-25684
dnsmasq General
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-358 1 PoC

A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a D

CVE-2020-25917
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

CVE-2020-26962
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

CVE-2020-25564
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature.

CVE-2020-22040
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.

CVE-2020-27180
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.

CVE-2020-16219
Delta Electronics TPEditor General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-125 1 PoC

Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-7227
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.

CVE-2020-24642
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-26536
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.

CVE-2020-26098
Software Genérico General
N/A
UNKNOWN
EPSS
9.8%
2020 1 PoC

cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

CVE-2020-27825
kernel General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-362 1 PoC

A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.

CVE-2020-6162
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.

CVE-2020-8635
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.

CVE-2020-36424
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

CVE-2020-6170
Software Genérico General
N/A
UNKNOWN
EPSS
9.8%
2020 2 PoCs

An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.