3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-36694
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2020 2 PoCs

An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.

CVE-2020-37198
Duplicate Cleaner Pro General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by injecting an oversized buffer into the license key field. Attackers can generate a 6000-byte payload and paste it into the license activation field to trigger an application crash.

CVE-2020-37192
MSN Password Recovery General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-611 1 PoC

MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.

CVE-2020-36198
Malware Remover General
6.7
MEDIUM
EPSS
0.9%
2020 CWE-77 1 PoC

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.

CVE-2020-37133
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Host property to trigger an application crash.

CVE-2020-37164
AbsoluteTelnet General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.

CVE-2020-37132
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.

CVE-2020-37128
ZOC Terminal General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and cause a denial of service.

CVE-2020-37131
Product Key Explorer General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash.

CVE-2020-14386
kernel General
6.7
MEDIUM
EPSS
0.6%
2020 CWE-787 4 PoCs

A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2020-7305
DLP ePO extension General
6.7
MEDIUM
EPSS
0.2%
2020 CWE-269 1 PoC

Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.

CVE-2020-37177
BOOTP Turbo General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.

CVE-2020-37130
Nsauditor General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field.

CVE-2020-37122
FTP Password Recover General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the application crash.

CVE-2020-11231
Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
6.7
MEDIUM
EPSS
0.0%
2020 1 PoC

Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-37213
TextCrawler Pro General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash.

CVE-2020-35164
Dell BSAFE Crypto-C Micro Edition General
6.7
MEDIUM
EPSS
0.7%
2020 CWE-385 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVE-2020-37121
Code::Blocks General
6.7
MEDIUM
EPSS
0.1%
2020 CWE-121 1 PoC

CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.

CVE-2020-36605
Hitachi Infrastructure Analytics Advisor General
6.6
MEDIUM
EPSS
0.0%
2020 CWE-276 1 PoC

Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local users to read and write specific files. This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00; Hitachi Ops Center Viewpoint: from 10.8.0-00 before 10.9.0-00.

CVE-2020-7316
File & Removable Media Protection (FRP) General
6.6
MEDIUM
EPSS
0.1%
2020 CWE-428 1 PoC

Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder. This issue may result in files not being encrypted when a policy is triggered.