3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-10761
QEMU: General
5.0
MEDIUM
EPSS
0.8%
2020 CWE-617 1 PoC

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.

CVE-2020-7251
Mcafee Endpoint Security (ENS) General
5.0
MEDIUM
EPSS
0.1%
2020 CWE-358 1 PoC

Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.

CVE-2020-7649
snyk-broker General
4.9
MEDIUM
EPSS
0.6%
2020 1 PoC

This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

CVE-2020-4839
8335-GTB General
4.9
MEDIUM
EPSS
0.7%
2020 1 PoC

IBM Host firmware for LC-class Systems is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A remote privileged attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 190037.

CVE-2020-8618
BIND9 General
4.9
MEDIUM
EPSS
1.3%
2020 1 PoC

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

CVE-2020-8619
BIND9 General
4.9
MEDIUM
EPSS
6.9%
2020 1 PoC

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attac

CVE-2020-8016
SUSE Linux Enterprise Module for Desktop Applications 15-SP1 General
4.9
MEDIUM
EPSS
0.1%
2020 CWE-367 2 PoCs

A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users to corrupt files or potentially escalate privileges. This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1.

CVE-2020-7258
Network Security Management (NSM) General
4.8
MEDIUM
EPSS
0.3%
2020 CWE-79 1 PoC

Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.

CVE-2020-36855
DCMTK General
4.8
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Upgrading to version 3.6.6 is sufficient to fix this issue. The identifier of the patch is 0fef9f02e. It is recommended to upgrade the affected component.

CVE-2020-7256
Network Security Management (NSM) General
4.8
MEDIUM
EPSS
0.3%
2020 CWE-79 1 PoC

Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.

CVE-2020-35167
Dell BSAFE Crypto-C Micro Edition General
4.8
MEDIUM
EPSS
0.7%
2020 CWE-200 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVE-2020-10059
zephyr General
4.8
MEDIUM
EPSS
0.4%
2020 CWE-295 1 PoC

The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.

CVE-2020-35168
Dell BSAFE Crypto-C Micro Edition General
4.7
MEDIUM
EPSS
0.1%
2020 CWE-311 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVE-2020-7744
com.mintegral.msdk:alphab General
4.7
MEDIUM
EPSS
0.2%
2020 3 PoCs

This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains malicious functionality in this module that tracks: 1. Downloads from Google urls either within Google apps or via browser including file downloads, e-mail attachments and Google Docs links. 2. All apk downloads, either organic or not. Mintegral listens to download events in Android's download manager and detects if the downloaded file's url contains: a. google.com or comes from a Google app (the com.android.vending package) b. Ends with .apk for apk downloads In both cases, the

CVE-2020-37211
Nsauditor SpotIM General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37207
Nsauditor SpotDialup General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37208
Nsauditor SpotFTP FTP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-787 1 PoC

SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.

CVE-2020-37206
Nsauditor ShareAlarmPro Advanced Network Access Control General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash when pasted into the registration key field.

CVE-2020-37180
Nsauditor GTalk Password Finder General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37185
Nsauditor Backup Key Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.