3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26105
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

CVE-2020-11953
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.

CVE-2020-5839
Symantec Endpoint Detection And Response General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

CVE-2020-14155
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVE-2020-26558
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

CVE-2020-11857
Operation Bridge Reporter. General
N/A
UNKNOWN
EPSS
63.2%
2020 1 PoC

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user

CVE-2020-26991
JT2Go General
N/A
UNKNOWN
EPSS
1.0%
2020 CWE-822 1 PoC

A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing ASM files. This could lead to pointer dereferences of a value obtained from untrusted source. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11899)

CVE-2020-11693
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.

CVE-2020-35229
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.

CVE-2020-5971
NVIDIA vGPU Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-27603
Software Genérico General
N/A
UNKNOWN
EPSS
26.3%
2020 1 PoC

BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

CVE-2020-26953
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVE-2020-25767
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does not check whether a domain name compression pointer is pointing within the bounds of the packet (e.g., forward compression pointer jumps are allowed), which leads to an Out-of-bounds Read, and a Denial-of-Service as a consequence.

CVE-2020-11259
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking

CVE-2020-16150
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.

CVE-2020-35227
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.

CVE-2020-14939
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.

CVE-2020-27631
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.

CVE-2020-6830
Firefox for iOS General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.

CVE-2020-6388
Chrome General
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.