3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-29127
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.

CVE-2020-7602
node-prompt-here General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.

CVE-2020-14022
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the "Application Starter" module) within the application.

CVE-2020-13815
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.

CVE-2020-3645
Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130

CVE-2020-12892
AMD Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.

CVE-2020-19003
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.

CVE-2020-8244
bl General
N/A
UNKNOWN
EPSS
1.1%
2020 CWE-126 2 PoCs

A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.

CVE-2020-16156
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

CPAN 2.28 allows Signature Verification Bypass.

CVE-2020-27693
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.

CVE-2020-13160
Software Genérico General
N/A
UNKNOWN
EPSS
88.8%
2020 3 PoCs

AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

CVE-2020-0451
Android General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9 Android-8.0 Android-8.1Android ID: A-158762825

CVE-2020-7905
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

CVE-2020-21531
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.

CVE-2020-3675
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ5018, IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCN7605, QCS404, QCS405, Rennell, SA415M, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250

CVE-2020-23478
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.

CVE-2020-16291
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16170
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.

CVE-2020-10228
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.

CVE-2020-14157
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 4 PoCs

The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm the wireless alarm system.