3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-27554
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device.

CVE-2020-27993
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.

CVE-2020-11265
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking

CVE-2020-7596
codecov npm module General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.

CVE-2020-6507
Chrome General
N/A
UNKNOWN
EPSS
26.3%
2020 2 PoCs

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-15496
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.

CVE-2020-8447
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

CVE-2020-16295
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-15578
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID is SVE-2020-17270 (July 2020).

CVE-2020-13782
Software Genérico General
N/A
UNKNOWN
EPSS
10.1%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

CVE-2020-35226
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.

CVE-2020-5760
Grandstream HT800 Series General
N/A
UNKNOWN
EPSS
5.0%
2020 CWE-78 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP message.

CVE-2020-24838
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.

CVE-2020-26887
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.

CVE-2020-11171
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-25780
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
57.3%
2020 0 PoCs

In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.

CVE-2020-26555
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

CVE-2020-35493
binutils General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-20 1 PoC

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

CVE-2020-12888
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

CVE-2020-13223
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.