3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7316
File & Removable Media Protection (FRP) General
6.6
MEDIUM
EPSS
0.1%
2020 CWE-428 1 PoC

Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder. This issue may result in files not being encrypted when a policy is triggered.

CVE-2020-36611
Hitachi Tuning Manager General
6.6
MEDIUM
EPSS
0.0%
2020 CWE-276 1 PoC

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS, Hitachi Tuning Manager - Agent for SAN Switch components) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-00.

CVE-2020-7259
McAfee Endpoint Security (ENS) General
6.6
MEDIUM
EPSS
0.0%
2020 CWE-264 1 PoC

Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file

CVE-2020-8834
Linux kernel General
6.5
MEDIUM
EPSS
0.1%
2020 CWE-368 1 PoC

KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were two commits that, according to the reporter, introduced the vulnerability: f024ee098476 ("KVM: PPC: Book3S HV: Pull out TM state save/restore into separate procedures") 87a11bb6a7f7 ("KVM: PPC: Book3S HV: Work around XER[SO] bug in fake suspend mode") The former landed in 4.8, the

CVE-2020-7762
jsreport-chrome-pdf General
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

This affects the package jsreport-chrome-pdf before 1.10.0.

CVE-2020-6093
Nitro Pro General
6.5
MEDIUM
EPSS
0.0%
2020 CWE-824 1 PoC

An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must open a malicious file.

CVE-2020-27298
Interventional Workspot General
6.5
MEDIUM
EPSS
0.2%
2020 CWE-78 1 PoC

Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.

CVE-2020-22661
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2020 1 PoC

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to erase the backup secondary official image and write secondary backup unauthorized image.

CVE-2020-13510
NZXT General
6.5
MEDIUM
EPSS
0.1%
2020 CWE-269 2 PoCs

An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) using the IRP 0x9c4060d0 gives a low privilege user direct access to the IN instruction that is completely unrestrained at an elevated privilege level. An attacker can send a malicious IRP to trigger this vulnerability.

CVE-2020-8622
BIND9 General
6.5
MEDIUM
EPSS
2.6%
2020 1 PoC

In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing

CVE-2020-35783
Software Genérico General
6.5
MEDIUM
EPSS
0.9%
2020 1 PoC

Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48. The NSDP protocol version allows unauthenticated remote attackers to obtain all the switch configuration parameters by sending the corresponding read requests.

CVE-2020-15117
synergy-core General
6.5
MEDIUM
EPSS
0.5%
2020 CWE-755 1 PoC

In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295) if the servers memory is less than 4 GB. It was verified that this issue does not cause a crash through the exception handler if the available memory of the Server is more than 4GB.

CVE-2020-4569
Security Key Lifecycle Manager General
6.5
MEDIUM
EPSS
0.1%
2020 1 PoC

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism. IBM X-Force ID: 184158.

CVE-2020-4782
WebSphere Application Server General
6.5
MEDIUM
EPSS
0.4%
2020 1 PoC

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

CVE-2020-7757
droppy General
6.5
MEDIUM
EPSS
0.4%
2020 1 PoC

This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.

CVE-2020-12521
AXC F 1152 (1151412) General
6.5
MEDIUM
EPSS
0.1%
2020 CWE-20 1 PoC

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.

CVE-2020-18899
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2020 1 PoC

An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.

CVE-2020-27545
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2020 1 PoC

libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line table in a crafted object.

CVE-2020-7770
json8 General
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

CVE-2020-26818
SAP NetWeaver AS ABAP (Web Dynpro) General
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.