3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-6078
Videolabs General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages in mdns_recv, the return value of the mdns_read_header function is not checked, leading to an uninitialized variable usage that eventually results in a null pointer dereference, leading to service crash. An attacker can send a series of mDNS messages to trigger this vulnerability.

CVE-2020-5360
Dell BSAFE Micro Edition Suite General
7.5
HIGH
EPSS
2.1%
2020 CWE-127 1 PoC

Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.

CVE-2020-8975
ZGR TPS200 NG General
7.5
HIGH
EPSS
0.2%
2020 CWE-201 1 PoC

ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access sensitive information about the system.

CVE-2020-8617
BIND9 General
7.5
HIGH
EPSS
92.6%
2020 5 PoCs

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an i

CVE-2020-4574
Security Key Lifecycle Manager General
7.4
HIGH
EPSS
0.3%
2020 1 PoC

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.

CVE-2020-4958
Security Identity Governance and Intelligence General
7.4
HIGH
EPSS
0.3%
2020 1 PoC

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.

CVE-2020-7778
systeminformation General
7.3
HIGH
EPSS
1.1%
2020 1 PoC

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.

CVE-2020-7260
Mcafee Application and Change Control (MACC) General
7.3
HIGH
EPSS
0.1%
2020 CWE-264 1 PoC

DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

CVE-2020-7679
casperjs General
7.3
HIGH
EPSS
0.8%
2020 3 PoCs

In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.

CVE-2020-28425
curljs General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package curljs.

CVE-2020-28470
@scullyio/scully General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

CVE-2020-12510
TwinCat XAR 3.1 General
7.3
HIGH
EPSS
0.2%
2020 CWE-276 1 PoC

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher pr

CVE-2020-28499
merge General
7.3
HIGH
EPSS
0.5%
2020 2 PoCs

All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .

CVE-2020-7736
bmoor General
7.3
HIGH
EPSS
0.8%
2020 2 PoCs

The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

CVE-2020-28433
node-latex-pdf General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package node-latex-pdf.

CVE-2020-4059
mversion General
7.3
HIGH
EPSS
2.1%
2020 CWE-77 1 PoC

In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This vulnerability is patched by version 2.0.0. Previous releases are deprecated in npm. As a workaround, make sure to escape git commit messages when using the commitMessage option for the update function.

CVE-2020-28462
ion-parser General
7.3
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-7737
safetydance General
7.3
HIGH
EPSS
0.4%
2020 2 PoCs

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

CVE-2020-28495
total.js General
7.3
HIGH
EPSS
6.1%
2020 1 PoC

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

CVE-2020-7788
ini General
7.3
HIGH
EPSS
0.3%
2020 2 PoCs

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.