3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-9362
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.

CVE-2020-9399
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux.

CVE-2020-25645
kernel General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-319 1 PoC

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.

CVE-2020-7466
MPD: FreeBSD PPP daemon General
N/A
UNKNOWN
EPSS
1.7%
2020 CWE-125 1 PoC

The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.

CVE-2020-11123
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8009W, APQ8017, APQ8037, APQ8053, APQ8064AU, APQ8096, APQ8096AU, APQ8096SG, APQ8098, MDM8207, MDM9150, MDM92

CVE-2020-16258
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

CVE-2020-16211
Advantech WebAccess HMI Designer General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-125 1 PoC

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

CVE-2020-5812
Tenable Nessus AMI General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

CVE-2020-8781
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.

CVE-2020-13813
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used.

CVE-2020-6445
Chrome General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVE-2020-25749
Software Genérico General
N/A
UNKNOWN
EPSS
3.9%
2020 1 PoC

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

CVE-2020-24386
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 2 PoCs

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVE-2020-14409
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

CVE-2020-15680
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.

CVE-2020-28864
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspecified impact via a long file name.

CVE-2020-12638
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption.

CVE-2020-20951
Software Genérico General
N/A
UNKNOWN
EPSS
7.2%
2020 1 PoC

In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

CVE-2020-13904
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.

CVE-2020-7200
HPE Systems Insight Manager (SIM) General
N/A
UNKNOWN
EPSS
85.5%
2020 2 PoCs

A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.