3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-15496
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.

CVE-2020-16295
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-13782
Software Genérico General
N/A
UNKNOWN
EPSS
10.1%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

CVE-2020-35226
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.

CVE-2020-5760
Grandstream HT800 Series General
N/A
UNKNOWN
EPSS
5.0%
2020 CWE-78 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP message.

CVE-2020-15570
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denial of service via a malformed crash file.

CVE-2020-8466
Trend Micro InterScan Web Security Virtual Appliance General
N/A
UNKNOWN
EPSS
27.3%
2020 1 PoC

A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.

CVE-2020-24838
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.

CVE-2020-26887
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.

CVE-2020-11171
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-25780
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
57.3%
2020 0 PoCs

In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.

CVE-2020-26555
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

CVE-2020-35493
binutils General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-20 1 PoC

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

CVE-2020-12888
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

CVE-2020-13223
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

CVE-2020-15774
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access Gradle Enterprise as that user.

CVE-2020-12674
Software Genérico General
N/A
UNKNOWN
EPSS
25.8%
2020 1 PoC

In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

CVE-2020-7485
TriStation TS1131 (v4.0.0 to v4.9.0, v4.10.0) General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version v4.9.1 and v4.10.1 released on May 30, 2013.1

CVE-2020-15531
Software Genérico General
N/A
UNKNOWN
EPSS
9.7%
2020 1 PoC

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.