3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7681
marscode General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.

CVE-2020-5351
Data Protection Advisor General
7.5
HIGH
EPSS
0.3%
2020 CWE-259 1 PoC

Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges.

CVE-2020-7768
grpc General
7.5
HIGH
EPSS
1.3%
2020 4 PoCs

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

CVE-2020-12524
BTP Touch Panel General
7.5
HIGH
EPSS
0.3%
2020 CWE-400 1 PoC

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

CVE-2020-7763
phantom-html-to-pdf General
7.5
HIGH
EPSS
0.4%
2020 2 PoCs

This affects the package phantom-html-to-pdf before 0.6.1.

CVE-2020-6086
Allen Bradley General
7.5
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.If the Simple Segment Sub-Type is supplied, the device treats the byte following as the Data Size in words. When this value represents a size greater than what remains in the packet data, the device enters a fault state where communication with the device is lost and

CVE-2020-27827
lldp/openvswitch General
7.5
HIGH
EPSS
0.5%
2020 CWE-400 1 PoC

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2020-6084
Allen-Bradley General
7.5
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability by sending an Electronic Key Segment with less bytes than required by the Key Format Table.

CVE-2020-11243
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

CVE-2020-28477
immer General
7.5
HIGH
EPSS
0.2%
2020 2 PoCs

This affects all versions of package immer.

CVE-2020-4979
QRadar SIEM General
7.5
HIGH
EPSS
0.6%
2020 1 PoC

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.

CVE-2020-7298
McAfee Total Protection (MTP) General
7.5
HIGH
EPSS
0.0%
2020 1 PoC

Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.

CVE-2020-6060
Mini-SNMPD General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply initiate multiple connections to the server.

CVE-2020-11255
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables

CVE-2020-11268
Snapdragon Auto, Snapdragon Mobile General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

CVE-2020-4269
Qradar General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-ForceID: 175845.

CVE-2020-16947
Microsoft Office 2019 General
7.5
HIGH
EPSS
45.4%
2020 4 PoCs

<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted tha

CVE-2020-7791
i18n General
7.5
HIGH
EPSS
1.5%
2020 1 PoC

This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.

CVE-2020-29500
PowerStore General
7.5
HIGH
EPSS
0.0%
2020 CWE-312 1 PoC

Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

CVE-2020-7772
doc-path General
7.5
HIGH
EPSS
0.8%
2020 1 PoC

This affects the package doc-path before 2.1.2.