3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-28588
Linux Kernel General
4.0
MEDIUM
EPSS
0.0%
2020 CWE-681 1 PoC

An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.

CVE-2020-7641
grunt-util-property General
4.0
MEDIUM
EPSS
0.1%
2020 1 PoC

This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

CVE-2020-7309
McAfee Application and Change Control General
3.9
LOW
EPSS
0.2%
2020 CWE-79 1 PoC

Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery section.

CVE-2020-5254
NetHack General
3.9
LOW
EPSS
9.3%
2020 CWE-125 1 PoC

In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.

CVE-2020-4066
Limdu General
3.8
LOW
EPSS
2.7%
2020 CWE-78 1 PoC

In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This has been patched in 0.95.

CVE-2020-13523
SoftPerfect General
3.8
LOW
EPSS
0.0%
2020 CWE-200 1 PoC

An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

CVE-2020-6197
SAP Enable Now General
3.8
LOW
EPSS
0.2%
2020 1 PoC

SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.

CVE-2020-15408
Software Genérico General
3.7
LOW
EPSS
0.2%
2020 2 PoCs

An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.

CVE-2020-9009
Software Genérico General
3.7
LOW
EPSS
0.4%
2020 1 PoC

The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.

CVE-2020-26422
Wireshark General
3.7
LOW
EPSS
0.3%
2020 2 PoCs

Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file

CVE-2020-1968
OpenSSL General
3.7
LOW
EPSS
1.0%
2020 6 PoCs

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer rec

CVE-2020-36636
Admin UI Module General
3.5
LOW
EPSS
0.3%
2020 CWE-79 1 PoC

A vulnerability classified as problematic has been found in OpenMRS Admin UI Module up to 1.4.x. Affected is the function sendErrorMessage of the file omod/src/main/java/org/openmrs/module/adminui/page/controller/systemadmin/accounts/AccountPageController.java of the component Account Setup Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 702fbfdac7c4418f23bb5f6452482b4a88020061. It is recommended to upgrade the affected component. VDB-216918 is the identifie

CVE-2020-36620
EnumStringValues General
3.5
LOW
EPSS
0.2%
2020 CWE-400 1 PoC

A vulnerability was found in Brondahl EnumStringValues up to 4.0.0. It has been declared as problematic. This vulnerability affects the function GetStringValuesWithPreferences_Uncache of the file EnumStringValues/EnumExtensions.cs. The manipulation leads to resource consumption. Upgrading to version 4.0.1 is able to address this issue. The name of the patch is c0fc7806beb24883cc2f9543ebc50c0820297307. It is recommended to upgrade the affected component. VDB-216466 is the identifier assigned to this vulnerability.

CVE-2020-36526
Countdown Timer General
3.5
LOW
EPSS
0.2%
2020 CWE-79 2 PoCs

A vulnerability classified as problematic was found in Countdown Timer. This vulnerability affects unknown code of the component Macro Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2020-36646
ZenLib General
3.5
LOW
EPSS
2.6%
2020 CWE-690 1 PoC

A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation of the argument Value leads to unchecked return value to null pointer dereference. Upgrading to version 0.4.39 is able to address this issue. The identifier of the patch is 6475fcccd37c9cf17e0cfe263b5fe0e2e47a8408. It is recommended to upgrade the affected component. The identifier VDB-217629 was assigned to this vulnerability.

CVE-2020-4324
Security Secret Server General
3.5
LOW
EPSS
0.1%
2020 1 PoC

IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515.

CVE-2020-36621
whatismyudid General
3.5
LOW
EPSS
0.2%
2020 CWE-707 1 PoC

A vulnerability, which was classified as problematic, has been found in chedabob whatismyudid. Affected by this issue is the function exports.enrollment of the file routes/mobileconfig.js. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is bb33d4325fba80e7ea68b79121dba025caf6f45f. It is recommended to apply a patch to fix this issue. VDB-216470 is the identifier assigned to this vulnerability.

CVE-2020-1775
OTRS General
3.5
LOW
EPSS
0.2%
2020 CWE-200 1 PoC

BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0.3 and prior versions, 7.0.17 and prior versions.

CVE-2020-7295
McAfee Web Gateway (MWG) General
3.5
LOW
EPSS
0.1%
2020 CWE-287 1 PoC

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.

CVE-2020-36524
Refined Toolkit General
3.5
LOW
EPSS
0.2%
2020 CWE-79 2 PoCs

A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown functionality of the component UI-Image/UI-Button. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.