3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-29031
GateManager General
7.1
HIGH
EPSS
0.2%
2020 CWE-280 1 PoC

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

CVE-2020-37036
RM Downloader General
7.1
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload with an egg hunter technique to bypass memory protections and execute commands like launching calc.exe.

CVE-2020-7745
MintegralAdSDK General
7.1
HIGH
EPSS
0.4%
2020 4 PoCs

This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitrary code on a user device.

CVE-2020-29505
Dell BSAFE Crypto-C Micro Edition General
7.1
HIGH
EPSS
0.5%
2020 CWE-331 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability.

CVE-2020-8968
Parallels Remote Application Server (Client) General
7.1
HIGH
EPSS
0.1%
2020 CWE-255 1 PoC

Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to recover the profile password.

CVE-2020-15702
apport General
7.0
HIGH
EPSS
0.0%
2020 CWE-367 1 PoC

TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges. Fixed in 2.20.1-0ubuntu2.24, 2.20.9 versions prior to 2.20.9-0ubuntu7.16 and 2.20.11 versions prior to 2.20.11-0ubuntu27.6. Was ZDI-CAN-11234.

CVE-2020-7862
HelpuViewer.exe General
7.0
HIGH
EPSS
0.6%
2020 CWE-20 1 PoC

A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.

CVE-2020-36938
WinAVR General
7.0
HIGH
EPSS
0.0%
2020 CWE-732 1 PoC

WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attackers can leverage the overly permissive access controls to potentially modify critical DLLs and executable files in the WinAVR installation directory.

CVE-2020-6295
SAP Adaptive Server Enterprise General
7.0
HIGH
EPSS
0.0%
2020 1 PoC

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compromise of the installed Cockpit. This compromise could enable the attacker to view, modify and/or make unavailable any data associated with the Cockpit, leading to Information Disclosure.

CVE-2020-1752
glibc General
7.0
HIGH
EPSS
0.1%
2020 CWE-416 1 PoC

A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.

CVE-2020-10023
zephyr General
6.9
MEDIUM
EPSS
0.4%
2020 CWE-120 1 PoC

The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel. See NCC-NCC-019 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.

CVE-2020-11023
🔥 KEV jQuery General
6.9
MEDIUM
EPSS
58.2%
2020 CWE-79 17 PoCs

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVE-2020-37086
Easy Transfer General
6.9
MEDIUM
EPSS
3.2%
2020 CWE-22 2 PoCs

Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system paths without authentication. Attackers can exploit the vulnerability by manipulating path parameters in GET and POST requests to list or download sensitive system files and inject malicious scripts into application parameters.

CVE-2020-36921
RED-V Super Digital Signage System RXV-A740R General
6.9
MEDIUM
EPSS
0.3%
2020 CWE-548 1 PoC

RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication.

CVE-2020-36888
Fusion Digital Signage General
6.9
MEDIUM
EPSS
0.0%
2020 CWE-203 2 PoCs

SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error responses.

CVE-2020-11022
jQuery General
6.9
MEDIUM
EPSS
2.5%
2020 CWE-79 17 PoCs

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVE-2020-36926
SmarterTools SmarterTrack General
6.9
MEDIUM
EPSS
0.1%
2020 CWE-497 1 PoC

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.

CVE-2020-36923
Sony BRAVIA Digital Signage General
6.9
MEDIUM
EPSS
0.2%
2020 CWE-639 1 PoC

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

CVE-2020-37127
dnsmasq-utils General
6.9
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters.

CVE-2020-11295
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
6.8
MEDIUM
EPSS
0.0%
2020 1 PoC

Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile